WPS PIN brute force¶
1. Context & stakes¶
Recover the WPA PSK via the WPS PIN (online brute or Pixie-Dust).
WPS was meant to simplify onboarding with an 8-digit PIN, but the protocol checks the PIN in two halves and reveals which half is wrong, collapsing the search space from 100 million to about 11000; Pixie-Dust reduces many APs to an offline computation. A recovered PIN yields the full WPA PSK no matter how strong it is. WPS shipped on by default on millions of consumer routers and remains a one-command compromise.
2. Theory¶
Wi-Fi Protected Setup joins a client with an 8-digit PIN validated in two halves, and the registrar reveals which half is wrong - cutting the search from 10^8 to ~11000. Pixie-Dust is worse: weak nonces/PRNG in some chipsets recover the PIN offline from a single exchange. A recovered PIN yields the full WPA passphrase.
3. Attack (PoC)¶
- Online PIN brute (reaver)
- Pixie-Dust offline PIN recovery
4. Detection¶
Indicators to watch, and the associated IDS rule (see
netlab-ids).
5. Defense¶
- Disable WPS
- PIN lockout / rate-limit
6. Exercise¶
This module is not replayable in the netns/veth lab - it needs real radio hardware. Build a wireless bench you fully own:
- A Wi-Fi adapter that supports monitor mode + injection (e.g. Atheros AR9271, MediaTek MT7612U); enable it with
sudo airmon-ng start wlan0. - A dedicated victim AP you own (a spare router, or a
hostapdsoft-AP) plus a throwaway client - never a third party's network. - Run the bench in a shielded / low-traffic area; attacking any network you do not own is illegal.
7. Further reading¶
- S. Viehboeck, Brute forcing WPS (2011)
- D. Bongard, Pixie-Dust offline PIN recovery (2014)
- reaver-wps-fork-t6x