25.3 WPA2 Handshake Capture and Offline Cracking
WPA2-PSK cracking cha marg asa: jevha ek device Wi-Fi la jodto, tevha 4-way handshake hoto. To handshake capture kela, ki attacker offline (Chapter 22 sarkha) wordlist ne passphrase try karto. Handshake madhe password nasto – password barobar asel tarach handshake match hoto.
# 1. capture on your network's channel (concept, your own Wi-Fi only)
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w mycap wlan0mon
# 2. force one of your own devices to reconnect so the handshake is captured
sudo aireplay-ng --deauth 5 -a AA:BB:CC:DD:EE:FF wlan0mon
# 3. crack the captured handshake against a wordlist
aircrack-ng -w /usr/share/wordlists/rockyou.txt mycap-01.cap
The whole point: if your passphrase is a long, random one not in any wordlist, this attack fails. A short or common passphrase (12345678, password) is cracked quickly. This is the single most important Wi-Fi lesson.
Deauth affects real devices
aireplay-ng --deauth knocks devices off the network. Do it only to your own devices on your own Wi-Fi. Deauthing others is jamming/interception and illegal.
Ravindra Bagale's Tip
Students get scared when they hear "WPA2 can be cracked". But remember: WPA2 itself is not broken – a weak password is. With a random passphrase of 16+ characters, it won't be found even if you run through all of rockyou.txt. The security lies in the password; the protocol is good.
Ravindra Bagale's Tip – मराठी
"WPA2 crack होतो" ऐकून students घाबरतात. पण लक्षात ठेवा: WPA2 तोडला जात नाही – कमकुवत password तोडला जातो. 16+ characters चा random passphrase असेल तर rockyou.txt पूर्ण चालवली तरी तो सापडत नाही. सुरक्षा password मध्ये आहे, protocol चांगला आहे.
Ravindra Bagale's Tip – हिंदी
"WPA2 crack होता है" सुनकर students घबरा जाते हैं. पर याद रखो: WPA2 नहीं टूटता – कमज़ोर password टूटता है. 16+ characters का random passphrase हो तो पूरी rockyou.txt चलाने पर भी वह नहीं मिलता. सुरक्षा password में है, protocol अच्छा है.
Lab
On your own Wi-Fi, capture your own handshake (steps above) and try to crack it with rockyou.txt. First with a weak temporary passphrase (see it crack), then with a long random one (see it fail). Change the router back to the strong passphrase afterwards.