ACT I - Hacking Wi-Fi Networks
Chapter 4 - Hacking Wi-Fi Networks
Most of the Wi-Fi hacking information out there on the Internet is outdated or people just don't know what they're talking about which can lead to confusion when trying to learn this shit. Furthermore, Kali has been updated and some syntax that is floating around on hacker forums no longer works which bogs people down in misinformation land. If I'm part of a group or forum and I see a thread on "How do I hack Wi-Fi networks?" I literally shit my pants in disbelief. Especially on a darknet hacking forum. Like how the fuck did you get here?
Wi-Fi hacking is one of the most annoying topics to answer in the forums but that being said getting everything to work properly is always a hurdle for many people out there which I take for granted. Having the right information that is up to date is something to be said so I've linked very helpful videos for you. Now keep in mind most of the stuff talked about in the videos will work (WEP and WPA/WPA2 attacks) except a few items but the point of watching the videos is to learn all the technicalities of Wi-Fi hacking for those wanting to know it all.
Instead of me explaining every technical detail about Wi-Fi hacking surrounding WEP, WPS, and WPA/WPA2/WPA3 Wi-Fi networks instead I'll direct you to an excellent resource as this topic has been explained, literally to death, across many hacker forums on the Internet.
Click below to watch the Wi-Fi hacking megaprimer on YouTube and watch up to Part 26.
You can follow along with the SecurityTube Megaprimer if you'd like but please note some attacks are outdated.
Click here - Wi-Fi hacking videos
If you want to go full austic mode to learn
EVERYTHING Wi-Fi related then create a free account on Z-Library and read away!
Click to Read - The Book of Wireless
You should have already purchased the required Wi-Fi hacking equipment explained in the last chapter (network cards and optional associated antennas) to continue with this course. If you haven't purchased the required items you should do that now because without having the right equipment following along with this chapter is a waste of time and cannot be completed. Remember to treat HackTown as a University or College course. Buy the supplies needed, do your home work, and complete the assignments! This will help you greatly. Don't just read everything and think now you know all this shit through and through. You don't know shit. Practice makes perfect. Put effort into what you're doing.
Alright let's start.
Open VirtualBox and fire up your Kali VM. Once Kali fully boots up plug in your Alfa network card one at a time into your laptop and once you've plugged them in go to "
File" - "
Devices" - "
USB Adaptor" to select the Alfa Wi-Fi network card and ensure it has a check mark beside it to ensure it's connected to the Kali VM so we can use it.
From here on in it's assumed you know what WEP, WPA/WPA2, and WPS networks are and their vulnerabilities. As attackers we like to start with the lowest hanging fruit and work our way from there. Finding WEP/WPS networks is fading out due to their insecurities but it's always a good idea to check around for it because you never know!
Recommended Wi-Fi hacking tool
You will need (2) wireless cards (Alfa cards) to maximize the next methods to the fullest. If you only have (1) Alfa network card you'll be limited in what you'll be able to attack.
Make sure you have
(2) wireless network cards plugged in and recognized in your Kali VM.
There's no need to manually put your Wi-Fi network cards into monitor mode first since the program discussed below will do it for you.
In Kali VM:
sudo wifite --kill
The "
--kill" option will stop any conflicting processes that may interfere with wifite. If you're familiar with aircrack-ng this is basically the same as using the "airmon-ng check kill" command.
Select the Wi-Fi network card to use and let the wifite tool run for around 60 seconds. Once that's done hit "
CTRL+C" and select the Wi-Fi network you're wanting to target. A nice feature of the wifite tool is instead of specifically targeting one Wi-Fi network at a time you can have wifite attack all the Wi-Fi networks in the area around you. Since this tool is automated you could kick back and do other things while this works in the background and goes after all the lowest hanging fruits around you. Very nice! Get high!
It's best to ensure there are clients already associated to the Wi-Fi network you're targeting to cycle through every attack (ie: WPA/WPA2).
If you don't see any clients come up on your screen you're either in the middle of nowhere OR most likely you didn't change your USB settings to 3.0 or 2.0 depending on your Wi-Fi card for the VM. Please ensure you're using the proper USB settings for your Alfa card on your VM or the Wi-Fi cards will not function as expected.
Wifite will try to crack the Wi-Fi networks you've selected and if it's able to obtain the 4-way handshake for the network it will automatically try a default wordlist against the password hopefully cracking the password. However, sometimes the default word list isn't good enough and you want to use something bigger.
Wi-Fi passwords require a minimum password of 8 characters to a max of 64 so we need to be using a wordlist that contains passwords that fit within that.
Below are more wordlists you can use if you absolutely need to give it 110% in cracking the Wi-Fi password:
https://weakpass.com/wordlists
Then you would specify the wordlist you want to use when running wifite like so:
sudo wifite --dict /path/to/wordlist
Any hotel you stay at, coffee house you sit at, friends place you go to, or anywhere you have a potential to use an Internet connection you should try hacking into every Wi-Fi network around you as possible so you have multiple networks you can use when online causing fucking havoc. Make sure you do this because you want to have multiple Wi-Fi networks that you can use for your own needs so you're not just relying on one network. The more Wi-Fi networks you have access to the better it is for you. Once you begin to add more and more Wi-Fi networks that you have taken over to your list you can start to use each Wi-Fi network at different dates and times. If you live in a dense urban area it's best to have 50+ Wi-Fi networks and use a different one each day, every other day, etc. Before you know it you'll be able to log into a Wi-Fi network that you won't be logging into again for well over 2 months. Constantly changing locations and Wi-Fi networks for your "business" activities makes you very difficult to locate if someone is onto your activities. Keep mobile.
Also, when you continue on to the next course the more Wi-Fi networks you're able to compromise and gain access to means the more victims you have to potentially infect with malware, extortion, ransomware, RATs, etc.
Build your Wi-Fi network empire every chance you can! If you travel or constantly move around you can see why this is important, better for your anonymity, and makes you difficult to track. Imagine the time and man power associated into finding and tracking you? The financial costs associated with this means you have to be a target that's worth the time, money, efforts, and worst-case scenario you're tracked to a geographical area, hacked Wi-Fi network, or a public Wi-Fi. Again, if you move around a lot, travel, or you're constantly on the move the better it will be for you. Once you begin to make a little money from your future criminal operations you'll be able to take the plunge into staying mobile and using the funds from your operations to fund your life. It's quite interesting once you hit this level of criminal.
Now at some point you're going to realize you're not able to crack every Wi-Fi network you come across and not every Wi-Fi network can be cracked or hacked. It depends on a lot of factors like signal strength, location, password complexity, etc.
Signal strength is very important when targeting Wi-Fi networks with success. The physical barriers that are between you and the target Wi-Fi network can, and will, interfere with your attacks. Just because you see a Wi-Fi network with great signal strength when using these programs can be misleading sometimes so keep an open mind when you see 100% signal strength. If you're unable to launch an attack against a Wi-Fi network it might be because of these reasons such as walls, metal, other radio interferences, objects, etc.
When you're using the tools needed to hack Wi-Fi networks you'll notice the Power/PWR level is displayed in "
dBi" or "
db" sometimes with a "-" sign before the number displayed. It doesn't matter which tool you plan on using (airodump-ng, wifite, etc.) since they all display the "Power" level a little differently but regardless they all represent the "db/dBi. Notice the power levels in the screenshots below that represent the aircrack-ng suite and wifite tools.


It's important to understand that a wireless antenna improves the transmission and reception of the radiofrequency (RF) signals giving you a reliable connection to the Wi-Fi network. The gain provided by an antenna is measured in Decibels Isotropic (dBi) which is what's represented when you're looking for wireless networks to connect to in order to determine which one has the best connection.
You'll soon find out some passwords you're just unable to crack due to the complexity of them (IE: a password of "12wedsW24#5$ETRgerfsf"). It's very common not being able to crack the WPA/WPA2 password if they've used a proper password to secure it. You can download massive WPA/WPA2 wordlists if you absolutely require access to the Wi-Fi network and want to try everything before giving up. We can do this by using hashcat to crack the WPA/WPA2 password.
We can utilize our Central Processing Units (CPU) to crack the WPA/WPA2 handshake file (.cap) with a wordlist of our choosing but this isn't the most efficient way of doing it. If you're using a computer that has a decent Graphics Processing Unit (GPU) we can crack passwords much faster and use larger wordlists for it.
If you really want onto that Wi-Fi network then you'll need to use a very large wordlist and let it rip using your GPU(s) to crack the password. To do this you can download hashcat and a massive WPA/WPA2 wordlist from the link provided in this chapter.
To utilize hashcat we must first turn the .cap file into a workable format for hashcat. Go to the directory that wifite saved the .cap file of the network you're trying to crack and have had no success using default wordlists on.
I saved the .cap file with the WPA/WPA2 handshake from wifite and named it "handshake.cap". Yours would be different of course.
aircrack-ng -j hashcat.hccapx handshake.cap
You now have a hccapx file which is meant only for hashcat. We'll now use the GPU on your host machine to increase password cracking significantly. If you are using Windows then download hashcat for Windows and use it like "hashcat.exe" with the examples below. Same same.
hashcat -m 22000 hashcat.hccapx WORDLIST
-m 22000 specifies the hash file type which in this case is related to WPA/WPA2 specifcally.
Now that you understand how to hack Wi-Fi networks go sit in a parking lot with a directional antenna pointed towards a foreign embassy and hack their shit you fucking spy.
If you cannot crack it then you'll want to move onto an "Evil Twin attack" to trick the users into entering their Wi-Fi password. You'll learn about this in the next chapter.
Click here to continue to Chapter 5