top of page

Hack WPA WPA2 WPS With Reaver Kali Linux: The Complete Manual


This article is only for an Educational purpose. Any actions and or activities related to the material contained within this Website is solely your responsibility.Misuse of the information in this website can result in criminal charges brought against the persons in question. The authors and will not be held responsible in the event any criminal charges be brought against any individuals misusing the information in this website to break the law.

Wireless networks are common in enterprise environments, making them a prime target for penetration testers. Additionally, misconfigured wireless networks can be easily cracked, providing penetration testers with a great deal of valuable information about the network and its users. This article explores some of the most widely-used tools for different aspects of wireless network hacking.

Hack WPA WPA2 WPS With Reaver Kali Linux

Wireless network hacking is an essential skill set for the modern penetration tester. While the tools described in this post are organized into categories, many have functionality that spans multiple different areas. Gaining familiarity with a few different wireless hacking tools can be a valuable investment in an ethical hacking career.

Now hacking WPA/WPA2 is a very tedious job in most cases. A dictionary attack may take days, and still might not succeed. Also, good dictionaries are huge. An exhaustive bruteforce including all the alphabets (uppercase lowercase) and numbers, may take years, depending on password length. Rainbow tables are known to speed things up, by completing a part of the guessing job beforehand, but the output rainbow table that needs to be downloaded from the net is disastrously large (can be 100s of GBs sometimes). And finally the security folks were at peace. But it was not over yet, as the new WPA technology was not at all easy for the users to configure. With this in mind, a new security measure was introduced to compliment WPA. Wifi Protected Setup (WPS). Now basically it was meant to make WPA even tougher to crack, and much easier to configure (push a button on router and device connects). However, it had a hole, which is now well known, and tools like reaver can exploit it in a single line statement. It still might take hours, but it is much better than the previous scenario in which months of brute-forcing would yield no result.

Reaver developers (reaver-wps-fork-t6x mod) are trying to correct this situation, several bugs have already been fixed in the latest release, but the work has not yet been completed. At the time of writing, it is recommended to use the Alfa AWUS036NHA wireless adapter with Reaver, since it has an Atheros AR9271 chipset that works great with Reaver.

Design flaws in many routers can allow hackers to steal Wi-Fi credentials, even if WPA or WPA2 encryption is used with a strong password. While this tactic used to take up to 8 hours, the newer WPS Pixie-Dust attack can crack networks in seconds. To do this, a modern wireless attack framework called Airgeddon is used to find vulnerable networks, and then Bully is used to crack them.

Reaver allowed a hacker to sit within range of a network and brute-force the WPS PIN, spilling all the credentials for the router. Worse, the 8-digit-long PIN could be guessed in two separate halves, allowing for the attack to take significantly shorter than working against the full length of the PIN.

While it did require a hacker to be within range of the target Wi-Fi network, it was able to penetrate even WPA and WPA2 networks with strong passwords using an online attack. This is opposed to an offline attack, such as WPA handshake brute-forcing, which does not require you to be connected to the network to succeed. While this was a limitation, the benefit is that there is typically no sign of this kind of attack to the average user.

Hardware-based attacks are a brilliant way of bypassing a strong password, and sustained interest in this attack vector continues to fuel the cat-and-mouse game between router manufacturers, ISPs, and the hackers trying to break into these devices. Learning the history of Reaver and the evolution to WPS Pixie-Dust-based attacks will keep you on the bleeding edge of Wi-Fi hacking and expand your hacking toolkit to enable you to take on any router with vulnerable WPS enabled.

I hope you enjoyed this guide to hacking WPS PINs with Airgeddon! If you have any questions about this tutorial or Airgeddon, feel free to leave a comment or reach me on Twitter @KodyKinzie. We'll be doing more in our Wi-Fi hacking series, so stay tuned.

Want to start making money as a white hat hacker? Jump-start your hacking career with our 2020 Premium Ethical Hacking Certification Training Bundle from the new Null Byte Shop and get over 60 hours of training from cybersecurity professionals.

A flaw in WPS, or WiFi Protected Setup, known about for over a year by TNS, was finally exploited with proof of concept code. Both TNS, the discoverers of the exploit and Stefan at .braindump have created their respective "reaver" and "wpscrack" programs to exploit the WPS vulnerability. From this exploit, the WPA password can be recovered almost instantly in plain-text once the attack on the access point WPS is initiated, which normally takes 2-10 hours (depending on which program you use).

and thats it... only three lines and it stops there with the curser blinking..I am immaging that reaver is working trying to find me the password, but is kinda strange just sittting here watching the cursor blinking waiting for magic...tell me is normal...or did i do something wrong again?

As for hacking wifi with Windows 8, you have a few options. Aircrack-ng has a Windows version, but I can't vouch for its effectiveness. Cain and Abel runs on Windows and is an excellent wifi cracking tool, but you need to buy a special wireless card that runs hundreds of dollars.

here we dont have linux how can i download from where?is it cost my pc data which i have now?one another question when i have pincode ssid bssid and mac numberhow long it will take hacking wifi?

Easiest way is download kali linux 32x from offensive security as an iso. Burn it and run it as a live boot disk. The default user is root and the password is toor. Onve its boots open terminal and type wifite. That will be a gui tool the rest is automatic. Both wps and wep can be hacked easily. However many new routers have recieved firmware upfates to block this method of attack so dont be expecting this to work. Finally if your wireless card does not support monitor mode then ur going to need to get a usb antenna may i suggest a signalking antenna . If you get it working then well done u have completed ur first task. If ur really good then use sdr to hack mobile phone calls. Both and more are very easy with kali linux. Most facebook viruses are made from the social engineering toolkit from kali. But reading is one thing. Actually doing it will land you in jail. Soo dont cry if you end up on the end of blacks willy. Happy hunting. :)

ok got it loaded on usb stick,it booted and started to install Kali linux but stops on "detecting network hardware" and goes no further.ant ideas please? I have no hardware,just a laptop trying to hack next doors wireless.

i have a question, in reaver when it tries the wps pins, i have an app that it can get me the router's pin without connecting to it, is there a way to enter that pin with reaver? or is there a difference between the pin i get and the pin that reaver tries?

I'm really dumb when it comes to technology, so bear with me here. I'm just curious..what is the point in hacking someone's wifi? is it just to be abl2 use their wifi 4 free or is there more 2 it than that? if so what all can u do when u hack someones wifi? I realize this is a really old post btw but just accidentally came across it

If you want to Pentest or Hack your Wifi Passwords, then the first thing you need is a compatible Wifi card. Most Wifi cards are priced between 15$-35$ USD.I see no point struggling with an unsupported card when you can just invest that extra bucks and that card will last you years. You get to learn how to pentest or hack Wifi passwords, how to Inject, spoof, setup fake AP or Honeypot. See the list of supported USB Wifi adapter cards that works in Kali Linux and are available in Amazon.

Here is a new video showing step by step how to crack the password on a router with WPA / WPA2 encryption. Kali Linux and Reaver are used so the router will have to have WPS enabled. Here are the commands used:airmon-ngairmon-ng start wlan0wash -i mon0 -Creaver -i mon0 -b (The BSSID) -vv

hlo sir i am beginner so plz tell me if i install kali linux in my laptop win 7 so win 7 deleted after install kali linuxhow to install kali linux in dual boot modeis there any problem in installing kali linux. like briking in androidi dont have wifi network or 3g sois internet required while installung kali linuxbut i manage a wifi connection to download software plz reply me sir plzzzzz. [email protected]

-WPS lock: (If the pin is set manually, not the factory settings)Run wash command: wash -i wlan0Then run reaver:reaver -b 00:11:22:33:44:55 -c 11 -i wlan0Now reaver is trying all possible combinations of the pin. Can take a long time. Even hours.Some routers will lock WPS after trying to crack the pin a couple of times. Most routers do not. But if a router gets locked you have to wait 'till the router unlocks. Sometimes it takes a minute or hours, but sometimes it can take days before a router unlocks.With a locked router, reaver will stop working. If you do ctrl C and run wash again, you can see that WPS is locked on the router. The simpelest way to solve that problem is to deauth all the devices on the target so they will think there is something wrong with the router and then restart the router again:aireplay-ng --deauth 1000000000000000000000 -a 00:11:22:33:44:55 wlan0(long number to deauth a long time)After the target reconnects again, start reaver again. 2ff7e9595c


Recent Posts

See All


bottom of page