The Risks of Using Pre-shared Keys for WPA/WPA2 Networks (2024)

What is performed from an attacker’s perspective?

Identify a PSK authenticated network

An attacker would initially need to identify a wireless network that uses PSK authentication. This can easily be performed by using the aircrack-ng suite of tools, specifically the airodump-ng tool. The first step of this process would be for an attacker to start a capable wireless card (or USB wireless adaptor) in monitor mode. This can be performed with the following command (as an example):

airmon-ng start wlan0

ifconfig wlan0 down

Once the device is in monitor mode, the main interface is taken down (as per the second command).

Identify the target network

The next step in the process is to identify a target network. Using the airodump-ng tool and only specifying the monitor interface (in this example, mon0) allows the device to hop between wireless channels. This is not ideal for capturing a specific network handshake but is useful to locate the specific channel for the next step:

airodump-ng mon0

The results would show several networks, each with varying signal strengths and configurations, but in our example, we will use channel 1 with the ‘SureCloud-WiFi’ AP.

Target the network

Our next step is to target this network. We do that by specifying additional arguments for airodump-ng:

airodump-ng mon0 –w surecloud-wifi-capture –channel 1

This command will capture wireless traffic to the file surecloud-wifi-capture-01.cap and will only focus on channel 1. Additional parameters can be specified, such as the use of –essid to target the network SSID name.

Once a handshake has been captured airodump-ng will note it at the top of the display. The next step following this is to clean up the capture file from any unnecessary packets not relating to the exchange and then convert it to a hashcat-capable format for GPU processing. The following commands can be used to do this:

# wpaclean [output file] [input file]
wpaclean surecloud-wifi-clean.cap surecloud-wifi-capture-01.cap

# aircrack-ng [input file] –J [output file]
aircrack-ng surecloud-wifi-clean.cap –J surecloud-wifi-hashcat

Using Hashcat is the most efficient way to perform password attacks such as dictionary attacks. How to use Hashcat is outside the scope of this article, but there are excellent resources available online:

What is the technical background of this process?

The key exchange handshake process uses several pieces of information, some of which are transferred over the air for the other device to make its necessary computations. This information includes:

  • Pairwise Master Key (SSID, PSK)
  • Authenticator Nonce (One-time key, generated by the Authenticator)
  • Supplicant Nonce (One-time key, generated by the Supplicant)
  • Authenticator MAC Address (Enumerated over the air)
  • Supplicant MAC Address (Enumerated over the air)

The Pairwise-Master-Key is never revealed over the air, but is used in a Pseudo-Random-Function alongside the key data (a concatenation of the Authenticator and Supplicant MAC addresses, and the Authenticator and Supplicant Nonces) to generate the Pairwise-Transient-Key.

As for the Pairwise-Transient-Key this is a 512 bit key, which is used to provide the following sub-keys:

  • Key-Confirmation-Key (First 128 bits)
  • Key-Encryption-Key (Second 128 Bits)
  • Temporal-Key (Third 128 Bits)
  • MIC Authenticator Tx Key (Fourth 64 bits) – Only used for TKIP
  • MIC Authenticator Rx Key (Fifth 64 bits) – Only used for TKIP

The Key-Confirmation-Key (KCK) is the key that is used for the creation of the Message Integrity Code (MIC), which is what is ultimately used for computing the PSK passphrase by password cracking tools. The MIC key itself is calculated using aHMAC-MD5algorithm.

The Risks of Using Pre-shared Keys for WPA/WPA2 Networks (2024)
Top Articles
What Is Bitcoin?
5 Cs of Credit (5 Cs of Banking) - The Strategic CFO®
What Is Single Sign-on (SSO)? Meaning and How It Works? | Fortinet
Drury Inn & Suites Bowling Green
Netr Aerial Viewer
Methstreams Boxing Stream
St Als Elm Clinic
Women's Beauty Parlour Near Me
Songkick Detroit
Nesb Routing Number
Clafi Arab
Craigslist Phoenix Cars By Owner Only
Valentina Gonzalez Leaked Videos And Images - EroThots
Cranberry sauce, canned, sweetened, 1 slice (1/2" thick, approx 8 slices per can) - Health Encyclopedia
Power Outage Map Albany Ny
Summoners War Update Notes
Dutch Bros San Angelo Tx
Brett Cooper Wikifeet
Weather Rotterdam - Detailed bulletin - Free 15-day Marine forecasts - METEO CONSULT MARINE
Apple Original Films and Skydance Animation’s highly anticipated “Luck” to premiere globally on Apple TV+ on Friday, August 5
Exl8000 Generator Battery
Directions To Nearest T Mobile Store
Обзор Joxi: Что это такое? Отзывы, аналоги, сайт и инструкции | APS
Powerschool Mcvsd
Https E22 Ultipro Com Login Aspx
Hdmovie2 Sbs
Expression Home XP-452 | Grand public | Imprimantes jet d'encre | Imprimantes | Produits | Epson France
Abga Gestation Calculator
CohhCarnage - Twitch Streamer Profile & Bio - TopTwitchStreamers
Ravens 24X7 Forum
Que Si Que Si Que No Que No Lyrics
Drabcoplex Fishing Lure
Die Filmstarts-Kritik zu The Boogeyman
KM to M (Kilometer to Meter) Converter, 1 km is 1000 m
Busch Gardens Wait Times
Bianca Belair: Age, Husband, Height & More To Know
Sam's Club Gas Prices Deptford Nj
Noaa Marine Weather Forecast By Zone
Ross Dress For Less Hiring Near Me
The Realreal Temporary Closure
The best specialist spirits store | Spirituosengalerie Stuttgart
Valls family wants to build a hotel near Versailles Restaurant
Fairbanks Auto Repair - University Chevron
2Nd Corinthians 5 Nlt
Citymd West 146Th Urgent Care - Nyc Photos
Youravon Com Mi Cuenta
Nurses May Be Entitled to Overtime Despite Yearly Salary
Treatise On Jewelcrafting
Image Mate Orange County
Samantha Lyne Wikipedia
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated:

Views: 6513

Rating: 4.3 / 5 (74 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.