Project Icon

hcxdumptool

无线网络数据包捕获与WPA协议分析工具

hcxdumptool是一款专用于捕获WLAN设备数据包和分析WiFi网络安全性的工具。它能在树莓派Zero等小型系统上高效运行,通过对WPA协议进行分析,捕获PMKID和完整握手包等关键信息。该工具主要用于在受控环境下进行WiFi网络安全分析,不建议在未经授权的网络中使用。结合hcxtools和Hashcat等工具,hcxdumptool为深入的网络安全研究提供了有力数据支持。

hcxdumptool

A tool to capture packets from WLAN devices and to discover potential weak points within own WiFi networks by running layer 2 attacks against the WPA protocol.

Designed to to run (mostly headless) on small systems like a Raspberry Pi Zero.

General Information

What Doesn't hcxdumptool Do?

  • It does not crack WPA PSK related hashes. (Use Hashcat or JtR to recover the PSK.)

  • It does not crack WEP. (Use the aircrack-ng suite instead.)

  • It does not crack WPS. (Use Reaver or Bully instead.)

  • It does not decrypt encrypted traffic. (Use tshark or Wireshark in parallel.)

  • It does not record all traffic captured on the WLAN device. (Use tshark or Wireshark in parallel.)

  • It does not perform Evil Twin attacks.

  • It does not provide a beautiful status display.

  • It is not a honey pot.

Unsupported: Windows OS, macOS, Android, emulators or wrappers!

[!NOTE]

hcxdumptool does not perform conversion or cracking! It is designed to be used in conjunction with the following tools:

ToolDescription
hcxpcapngtoolTool to convert raw PCAPNG files to Hashcat and JtR readable formats. (hcxtools)
hcxhashtoolTool to filter hashes from HC22000 files based on user input. (hcxtools)
hcxpsktoolTool to get weak PSK candidates from HC22000 files. (hcxtools)
hcxeiutoolTool to calculate wordlists based off ESSIDs gathered. (hcxtools)
Hashcat/JtRThird party tools used to infer PSK from HC22000 hash files.

hcxtools can be found here. Hashcat can be found here.

Work Flow

hcxdumptool -> hcxpcapngtool -> hcxhashtool (additional hcxpsktool/hcxeiutool) -> Hashcat or JtR

Requirements

  • Knowledge of radio technology.
  • Knowledge of electromagnetic-wave engineering.
  • Detailed knowledge of 802.11 protocol.
  • Detailed knowledge of key derivation functions.
  • Detailed knowledge of Linux.
  • Detailed knowledge of filter procedures. (Berkeley Packet Filter, capture filter, display filter, etc.)
  • Detailed knowledge of Bolean Operators.
  • Operating system: Linux (recommended: kernel >= 6.6, mandatory: kernel >= 5.15)
  • Recommended: Arch Linux (notebooks and desktop systems), OpenWRT (small systems like Raspberry Pi, WiFi router)
  • WLAN device chipset must be able to run in monitor mode. MediaTek chipsets are preferred due to active monitor mode capabilities.
  • WLAN device driver must support monitor and full frame injection mode.
  • gcc >= 14 recommended (deprecated versions are not supported: https://gcc.gnu.org/)
  • make
  • libpcap and libpcap-dev (If internal BPF compiler has been enabled.)
  • Raspberry Pi A, B, A+, B+, Zero (WH). (Recommended: Zero or A+, because of a very low power consumption), but notebooks and desktops will work as well.
  • GPIO hardware mod recommended (push button and LED) on Raspberry Pi
  • To allow 5/6/7GHz packet injection, it is mandatory to uncomment a regulatory domain that support this: /etc/conf.d/wireless-regdom
  • Make sure that the version of hcxdumptool always fits to the version of hcxpcapngtool

Install Guide

[!IMPORTANT]

While hcxdumptool and hcxtools are available through the package manager on most distributions, these packages are usually very old and outdated, thus cloning and building is recommended.

Make sure that your distribution is updated to it's latest version and make sure that all header files and dependencies have been installed BEFORE attempting to compile!

The packages mentioned in the "Requirements" section sometimes come under different names in a package manager! Make sure to install the correct packages!

Clone Repository

git clone https://github.com/ZerBea/hcxdumptool.git
cd hcxdumptool

Compile & Install

Compiling:

make -j $(nproc)

Installing to /usr/bin:

make install (as super user)

Or installing to /usr/local/bin:

make install PREFIX=/usr/local (as super user)

[!TIP]

On headless operation, remove -DSTATUSOUT from the Makefile before compiling! That way, the status display will not be compiled. This will save CPU cycles and prevent ERRORs from occurring.

It is theoretically possible to compile hcxdumptool for other systems (e.g. Android) and other distributions (e.g. KALI) and other operating systems (BSD) as well. There is no plan to support the operating systems and feature requests will be rejected.

Adapters

[!WARNING]

  • Do not expect flawless drivers on brand new hardware!

  • Driver must support monitor mode and full packet injection!

  • PRISM devices are not supported!

  • WIRELESS EXTENSIONS are deprecated and no longer supported!

[!NOTE]

Manufacturers do change chipsets without changing model numbers. Sometimes they add (v)ersion or (rev)vision.

Preferred chipsets come from MediaTek due to active monitor mode being very reliable. (Important notice: Massive problems with MT76 USB 3.0 devices if connected to some USB 3.0 ports!)

Always verify the actual chipset with 'lsusb' and/or 'lspci'!

No support for a third party driver which is not part of the official Linux kernel (https://www.kernel.org/) Report related issues to the site, from which you downloaded the driver.

No support for a driver which doesn't support monitor mode and full frame injection natively. If you need these features, do a request on www.kernel.org

Some device and driver tests can be found here.

Recommended WiFi chipsets:

  • MediaTek (mt76) depending on the version of the Linux Kernel expect massive driver issues

  • Ralink (rt2800usb) old chipset

  • Atheros (ath9k_htc) old chipset

Not recommended WiFi chipsets:

  • Realtek (Monitor mode and frame injection problems.)

  • Intel (Monitor mode and frame injection problems.)

  • Broadcom (Neither monitor mode nor frame injection by official Linux kernel.)

  • Qualcomm (No frame injection by official Linux kernel.)

More information about possible issues or limitations can be found here.

Antennas

The best high frequency amplifier is a good antenna!

It is much better to achieve gain using a good antenna instead of increasing transmission power.

VENDOR MODELTYPE
LOGILINK WL0097Grid Parabolic
TP-LINK TL-ANT2414 A/BPanel
LevelOne WAN-1112Panel
DELOCK 88806Panel
TP-LINK TL-ANT2409 APanel

GPS devices (NMEA 0183 protocol)

VENDOR MODELTYPE
NAVILOCK NL-701USUSB
JENTRO BT-GPS-8 activepilotBLUETOOTH
HiLetgo VK172USB

Useful Scripts

ScriptDescription
stopnmExample script to start NetworkManager
startnmExample script to stop NetworkManager
startnlmonExample script to activate NETLINK monitor

Caution!

You might expect me to recommend that everyone should be using hcxdumptool/hcxtools. But the fact of the matter is, hcxdumptool/hcxtools is NOT recommended to be used by inexperienced users or newbies.

If you are not familiar with Linux in general or you do not have at least a basic level of knowledge as mentioned in the "Requirements" section, hcxdumptool/hcxtools is probably not what you are looking for. However, if you have that knowledge hcxdumptool/hcxtools can do magic for you.

Misuse of hcxdumptool within a network, particularly without authorization, may cause irreparable damage and result in significant consequences. “Not understanding what you were doing” is not going to work as an excuse.

The entire toolkit (hcxdumptool and hcxtools) is designed to be an analysis toolkit.

hcxdumptool should only be used in a 100% controlled environment!

If you can't control the environment, it is absolutely mandatory to set the BPF!

The BPF can be used to select a target (or multible targets) or to protect devices.

By default, hcxdumptool is utilizing three attack vectors:

  • Connecting to an ACCESS POINT to get a PMKID (turn off by --attemptapmax)

  • Disconnecting a CLIENT from an associated ACCESS POINT to get a complete handshake (M1M2M3M4) and a PMKID (turn off by --attemptapmax)

  • Allowing a CLIENT to connect to hcxdumptool to get a challenge (M1M2) or an EAP-ID (turn off by --attemptclientmax)

[!WARNING]

You may only use hcxdumptool on networks that you have permission to attack, because:

  • hcxdumptool is able to prevent complete WLAN traffic transmission. (Depending on selected options.)

  • hcxdumptool is able to capture PMKIDs from access points. (Only one single PMKID from an access point is required. Use hcxpcapngtool to convert them to a format Hashcat or JtR understands.)

  • hcxdumptool is able to capture handshakes from non-connected clients. (Only one single M2 from the client is required. Use hcxpcapngtool to convert them to a format Hashcat or JtR understands.)

  • hcxdumptool is able to capture handshakes from 5/6GHz clients on 2.4GHz. (Only one single M2 from the client is required. Use hcxpcapngtool to convert to a format Hashcat or JtR understands.)

  • hcxdumptool is able to capture passwords from the WLAN traffic. (Use hcxpcapngtool -R to save them to file, or together with networknames [-E].)

  • hcxdumptool is able to request and capture extended EAPOL. (RADIUS, GSM-SIM, WPS. hcxpcapngtool will show you information about them.)

  • hcxdumptool is able to capture identities from the WLAN traffic. (Example: Request IMSI numbers from mobile phones - use hcxpcapngtool -I to save them to file.)

  • hcxdumptool is able to capture usernames from the WLAN traffic. (Example: User name of a server authentication - use hcxpcapngtool -U to save them to file.)

Do Not:

  • Use a logical interface and leave the physical interface in managed mode!

  • Use hcxdumptool in combination with the aircrack-ng suite, Reaver, Bully, or any other tools that take access to the interface!

  • Use tools like macchanger as they are useless since hcxdumptool uses its own random MAC address space.

  • Merge PCAPNG dumpfiles because doing so will destroy custom block hash assignments!

Useful Links

项目侧边栏1项目侧边栏2
推荐项目
Project Cover

豆包MarsCode

豆包 MarsCode 是一款革命性的编程助手,通过AI技术提供代码补全、单测生成、代码解释和智能问答等功能,支持100+编程语言,与主流编辑器无缝集成,显著提升开发效率和代码质量。

Project Cover

AI写歌

Suno AI是一个革命性的AI音乐创作平台,能在短短30秒内帮助用户创作出一首完整的歌曲。无论是寻找创作灵感还是需要快速制作音乐,Suno AI都是音乐爱好者和专业人士的理想选择。

Project Cover

有言AI

有言平台提供一站式AIGC视频创作解决方案,通过智能技术简化视频制作流程。无论是企业宣传还是个人分享,有言都能帮助用户快速、轻松地制作出专业级别的视频内容。

Project Cover

Kimi

Kimi AI助手提供多语言对话支持,能够阅读和理解用户上传的文件内容,解析网页信息,并结合搜索结果为用户提供详尽的答案。无论是日常咨询还是专业问题,Kimi都能以友好、专业的方式提供帮助。

Project Cover

阿里绘蛙

绘蛙是阿里巴巴集团推出的革命性AI电商营销平台。利用尖端人工智能技术,为商家提供一键生成商品图和营销文案的服务,显著提升内容创作效率和营销效果。适用于淘宝、天猫等电商平台,让商品第一时间被种草。

Project Cover

吐司

探索Tensor.Art平台的独特AI模型,免费访问各种图像生成与AI训练工具,从Stable Diffusion等基础模型开始,轻松实现创新图像生成。体验前沿的AI技术,推动个人和企业的创新发展。

Project Cover

SubCat字幕猫

SubCat字幕猫APP是一款创新的视频播放器,它将改变您观看视频的方式!SubCat结合了先进的人工智能技术,为您提供即时视频字幕翻译,无论是本地视频还是网络流媒体,让您轻松享受各种语言的内容。

Project Cover

美间AI

美间AI创意设计平台,利用前沿AI技术,为设计师和营销人员提供一站式设计解决方案。从智能海报到3D效果图,再到文案生成,美间让创意设计更简单、更高效。

Project Cover

AIWritePaper论文写作

AIWritePaper论文写作是一站式AI论文写作辅助工具,简化了选题、文献检索至论文撰写的整个过程。通过简单设定,平台可快速生成高质量论文大纲和全文,配合图表、参考文献等一应俱全,同时提供开题报告和答辩PPT等增值服务,保障数据安全,有效提升写作效率和论文质量。

投诉举报邮箱: service@vectorlightyear.com
@2024 懂AI·鲁ICP备2024100362号-6·鲁公网安备37021002001498号