# Pwning WPA/WPA2 Networks With Bettercap and the PMKID Client-Less Attack

DevFeed: [Pwning WPA/WPA2 Networks With Bettercap and the PMKID Client-Less Attack](<https://devfeed.tech/articles/pwning-wpa-wpa2-networks-with-bettercap-and-the-pmkid-client-less-attack-41261.md>)

Original publisher: [Read original article](<https://www.evilsocket.net/2019/02/13/Pwning-WiFi-networks-with-bettercap-and-the-PMKID-client-less-attack/>)

Author: Simone Margaritelli

Published: 2019-02-13T15:53:31Z

Content type: tutorial

Language: en

Sources: [evilsocket](<https://devfeed.tech/sources/evilsocket.md>)

Topics: [Networks](<https://devfeed.tech/topics/networks.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [client](<https://devfeed.tech/topics/client.md>), [GPU](<https://devfeed.tech/topics/gpu.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [bettercap](<https://devfeed.tech/tags/bettercap.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [deauth](<https://devfeed.tech/tags/deauth.md>), [handshake](<https://devfeed.tech/tags/handshake.md>), [hashcat](<https://devfeed.tech/tags/hashcat.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [monitor-mode](<https://devfeed.tech/tags/monitor-mode.md>), [networks](<https://devfeed.tech/tags/networks.md>), [packet-injection](<https://devfeed.tech/tags/packet-injection.md>), [password-cracking](<https://devfeed.tech/tags/password-cracking.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pmkid](<https://devfeed.tech/tags/pmkid.md>), [rsn](<https://devfeed.tech/tags/rsn.md>), [rsn-pmkid](<https://devfeed.tech/tags/rsn-pmkid.md>), [wifi-hacking](<https://devfeed.tech/tags/wifi-hacking.md>), [wireless-security](<https://devfeed.tech/tags/wireless-security.md>), [wpa](<https://devfeed.tech/tags/wpa.md>), [wpa2](<https://devfeed.tech/tags/wpa2.md>)

## AI overview

This tutorial explains new WiFi features in bettercap, including automated EAPOL handshake capture and a PMKID client-less attack against WPA/WPA2 access points. It also covers deauthentication-based capture workflows and preparing captured files for hashcat password cracking.

## Source excerpt

In this post, I'll talk about the new WiFi related features that have been recently implemented into bettercap, starting from how the EAPOL 4-way handshake capturing has been automated, to a whole new type of attack that will allow us to recover WPA PSK passwords of an AP without clients. We'll start with the assumption that your WiFi card supports monitor mode and packet injection (I use an AWUS1900 with this driver), that you have a working hashcat (v4.2.0 or higher is required) installation (ideally with GPU support enabled) for cracking and that you know how to use it properly either for dictionary or brute-force attacks, as no tips on how to tune the masks and/or generate proper dictionaries will be given :) On newer macOS laptops, the builtin WiFi interface `en0` already supports monitor mode, meaning you won't need a Linux VM in order to run this :)