Wireless Hacking
2 min readArticle
Wireless hacking encompasses attacks against any radio frequency communication — WiFi (802.11), Bluetooth, RFID/NFC, cellular, and custom RF protocols. The key advantage over wired attacks: you don't need physical access to the cable. Just proximity.
Categories
WiFi Hacking
The most common wireless attack surface:
- WPA/WPA2 — handshake capture, dictionary cracking, PMKID attack
- WPS — Pixie Dust, PIN brute force, Null PIN
- Evil Twin / KARMA — rogue AP, credential harvesting
- WPA3 — downgrade attacks, Dragonblood
- War Driving — passive network mapping
- Automated Tools — Wifite, Airgeddon, Lazy-Script
- Remote WiFi Hacking — Pi drop boxes, Netcat tunnels
Bluetooth Hacking
- BLE (Bluetooth Low Energy) sniffing and MITM
- Classic Bluetooth attacks
- Bluebugging, Bluejacking, Bluesnarfing
- BtleJuice, Ubertooth, Wireshark with Bluetooth
RFID and NFC
- Access card cloning
- NFC relay attacks
- Proxmark3, Flipper Zero, ACR122U
SDR - Software Defined Radio
- RTL-SDR for passive monitoring
- HackRF for active TX/RX attacks
- Replay attacks against RF remotes
- Signal analysis with GNU Radio
HackRF One
- Full-duplex SDR hardware
- 1 MHz – 6 GHz range
- Replay attacks, custom signal generation
Required Hardware
| Device | Purpose | Cost |
|---|---|---|
| Alfa AWUS036ACH | WiFi attacks (monitor mode + injection) | ~$40 |
| Alfa AWUS036ACS | WiFi (dual-band) | ~$50 |
| RTL-SDR v3 | Passive RF listening | ~$30 |
| HackRF One | Active RF attacks | ~$300 |
| Proxmark3 | RFID/NFC cloning | ~$300 |
| Flipper Zero | Multi-protocol (sub-GHz, NFC, IR, BLE) | ~$170 |
| Raspberry Pi 4 | Wireless attack platform | ~$55 |
Essential Software Stack
bash
# WiFi toolkit
sudo apt install aircrack-ng reaver bully hcxdumptool hcxtools \
wifite hostapd dnsmasq tshark wireshark
# Clone Airgeddon
git clone https://github.com/v1s1t0r1sh3r3/airgeddon
# SDR tools
sudo apt install rtl-sdr gnuradio gqrx hackrf
# Bluetooth tools
sudo apt install bluez bluetooth wireshark
Monitor Mode Cheat Sheet
bash
# Enable monitor mode
sudo airmon-ng check kill
sudo airmon-ng start wlan0
# Interface is now wlan0mon
# Or manually
sudo ip link set wlan0 down
sudo iw wlan0 set monitor control
sudo ip link set wlan0 up
# Verify
iwconfig wlan0mon | grep -i monitor
# Disable monitor mode
sudo airmon-ng stop wlan0mon
Legal and Ethical Notes
All wireless attacks require authorization from the network/device owner. Unauthorized interception of radio communications is illegal in virtually every jurisdiction (wiretapping laws, Computer Fraud and Abuse Act, etc.).
Always get written permission before:
- Scanning/monitoring networks you don't own
- Attempting to crack any credentials
- Performing any active wireless attack
Sub-pages
- wifi-hacking/index — WiFi hacking
- bluetooth-hacking — Bluetooth attacks
- rfid-nfc-tools — RFID/NFC tools
- software-defined-radio-sdr — Software Defined Radio
- hackrf-sdr-attack-tool — HackRF One hardware
techzonesite.comUnlock Your IT Potential