Skip to content

Capturing Handshakes

Wireless network security analysis often hinges on capturing and analyzing handshakes, which reveal critical authentication details. This section demonstrates how to capture WPA2/WPA3 handshakes using packet sniffing tools and analyze them for vulnerabilities, such as weak passwords or misconfigurations. The process is critical for understanding how attackers exploit wireless authentication weaknesses and how defenders can mitigate them.


Capturing WPA/WPA3 Handshakes

Tools and Setup

Use packet sniffing tools like airodump-ng (from the Aircrack-ng suite) or tcpdump to capture handshake packets. Ensure your wireless interface is in monitor mode:

sudo airmon-ng start wlan0  # Put interface in monitor mode

Capturing the Handshake

  1. Monitor the network:

    sudo airodump-ng --channel 6 --bssid 00:11:22:33:44:55 -w capture mon0
    
    Replace 00:11:22:33:44:55 with the target access point's MAC address. This command captures packets and saves them to capture-01.cap, capture-02.cap, etc.

  2. Force a reassociation:
    Use aireplay-ng to deauthenticate a client, forcing it to reconnect and trigger the handshake:

    aireplay-ng -0 10 -a 00:11:22:33:44:55 -c 11:22:33:44:55:66 mon0
    
    Replace 11:22:33:44:55:66 with the client's MAC address. This step is optional but increases the likelihood of capturing the handshake.

  3. Capture via tcpdump:
    For alternative analysis, use tcpdump to save handshake packets:

    sudo tcpdump -i mon0 -w handshake.pcap -f 'tcp port 80'  # Example filter
    
    Adjust the filter to capture WPA-specific packets (e.g., wlan type mgmt subtype auth).


Analyzing Captured Handshakes

Identifying Vulnerabilities

  1. Check for handshake files:
    Use airodump-ng to verify if the handshake was captured:

    airodump-ng -c 6 -w capture mon0
    
    Look for a file named capture-01.cap (WPA2) or capture-01.cap (WPA3).

  2. Analyze WPA2 handshakes:
    Use aircrack-ng to attempt dictionary attacks:

    aircrack-ng -w /path/to/wordlist capture-01.cap
    
    If the password is in the wordlist, the tool will crack the handshake.

  3. WPA3-specific considerations:
    WPA3 uses Simultaneous Authentication of Equals (SAE), which is more secure. However, tools like WPA3-Handshake-Analyzer (Python-based) can analyze SAE handshakes for vulnerabilities like weak passwords or misconfigured PSKs.

Cracking the Handshake

For WPA2, the four-way handshake is the target. For WPA3, the handshake involves a more complex exchange, but the same principles apply:
- Use dictionary attacks if the password is simple.
- Use hybrid attacks with custom rules for stronger passwords.


Key takeaways

  • Use packet sniffing tools like airodump-ng and tcpdump to capture WPA/WPA3 handshakes during client association.
  • Analyze captured data for vulnerabilities like weak passwords or misconfigurations using tools like aircrack-ng.
  • WPA3 handshakes are more secure but require specialized analysis techniques.
  • Always ensure authorized testing and compliance with legal frameworks when performing these activities.