Wireless Penetration Testing
Comprehensive WiFi, Bluetooth, and RF security assessment guide covering WPA/WPA2/WPA3 cracking, evil twin attacks, BLE exploitation, WPS attacks, captive portal bypass, and cutting-edge wireless attacks.
Why This Matters
Legal Warning
What You'll Learn
- Monitor mode, recon, and packet capture
- WPA2/WPA3 cracking: handshake, PMKID, and deauth capture
- Evil twin, WPA-Enterprise, WPS, and captive portal bypass
- Bluetooth/BLE and SDR/RF sub-GHz replay attacks
- Modern standards: WPA3-SAE, Wi-Fi 6E/7 MLO, and 6 GHz
- Advanced attacks: KRACK, FragAttacks, Dragonblood, SSID Confusion
Methodology Overview
Guide Sections
Setup
Hardware selection, driver installation, VM passthrough. → End state: wlan0mon ready for injection
● BeginnerReconnaissance
airodump-ng scanning, hidden SSID probing, client enumeration. → Tools: airodump-ng, Kismet
● BeginnerWPA Cracking
4-way handshake, PMKID (clientless), GPU cracking. → Tools: aircrack-ng, hashcat
● IntermediateEvil Twin
Rogue AP setup, KARMA/MANA & known-beacon, captive portal credential harvesting. → Tools: hostapd-wpe, Fluxion, eaphammer
● IntermediateEnterprise
802.1X/RADIUS attacks, EAP credential capture, MSCHAP cracking. → Tools: eaphammer, hostapd-wpe
● AdvancedDeauth Attacks
Force client disconnection, handshake harvesting, DoS. → Tools: aireplay-ng, MDK4, Bettercap
● IntermediateWEP Cracking
Legacy IV-capture + ARP replay attacks. Included for legacy system testing. → Tools: aircrack-ng
● BeginnerWPA3, Wi-Fi 6 & 7
SAE/Dragonblood side-channel, OWE downgrade, 6 GHz scanning, Wi-Fi 7 MLO. → Tools: hcxdumptool, hashcat
● AdvancedSDR & RF Hacking
RTL-SDR/HackRF signal analysis, replay attacks, garage/car fob interception. → Tools: GQRX, URH, Flipper Zero
● AdvancedBluetooth & BLE
BLE MITM, BlueBorne, device tracking, Classic BT PIN attacks. → Tools: Ubertooth, btlejack, bettercap
● IntermediateWPS Attacks
Pixie Dust (offline), Reaver PIN brute force, default vendor PINs. → Tools: Reaver, Bully, wifite2
● IntermediateCaptive Portal Bypass
MAC clone, DNS tunnel, HTTPS bypass for hotel/airport portals. → Tools: macchanger, iodine, sshuttle
● IntermediateAdvanced Attacks
KRACK, FragAttacks, SSID Confusion, mesh/Wi-Fi Direct, drone hijacking. → CVEs: 2017-13077, 2020-24588, 2023-52424
● AdvancedTools & Hardware
40+ tools, recommended adapters, SDR hardware, Bluetooth sniffers. → Includes: Alfa, HackRF, Ubertooth
● BeginnerPost-Exploitation
Pivoting, ARP spoofing, NTLM relay, lateral movement from wireless to wired. → Tools: Responder, ntlmrelayx, bettercap
● AdvancedRelated Tools
Interactive companions for the capture-to-crack workflow and post-compromise pivoting.
Wi-Fi Command Builder
Generate copy-ready aircrack-ng, hcxdumptool, hashcat, reaver, and eaphammer commands for the capture-to-crack workflow.
MAC Address Analyzer
Identify adapter and client vendors by OUI while triaging airodump output and spoofing addresses.
Hash Generator
Generate and identify hashes when validating captured PMKID/EAPOL material before feeding hashcat.
Subnet Calculator
Work out ranges and segmentation once you pivot from a compromised wireless foothold into the wired network.
Legal Disclaimer
Wireless attacks can affect nearby networks and devices. Only perform these attacks on networks you own or have explicit written authorization to test.
Related Topics
Physical Security
Often combined with wireless attacks for full physical/digital assessments.
Internal Network Pentesting
Post wireless compromise, pivot to internal network testing.
IoT Pentesting
Many IoT devices use WiFi, Bluetooth, Zigbee, and other wireless protocols.
Lab Setup
Build isolated wireless labs for safe practice.