A new way to crack WPA/WPA2 security protocols has been discovered by security researcher and creator of the password cracking tool Hashcat, Jens 'Atom' Steube. This new technique makes cracking WiFi passwords on most modern routers easier and faster than ever.
The attack technique
According to the researcher, the new attack technique does not rely on traditional methods used to steal Wi-Fi passwords. Currently, the most popular attack method works against the 4-way handshake that is performed when client devices, such as a smartphone or laptop, try to connect to the Wi-Fi network. Once the client attempts to connect and the 4-way handshake authentication of EAPOL (authentication protocol) takes place, attackers capture this information in order to brute-force the password used.
Instead, the new technique is executed in the Robust Security Network Information Element (RSN IE) of a single EAPOL frame and does not require the existence of a client or user participation at any stage.
[su_note note_color=”#fcfcd8″ text_color=”#494134″ radius=”1″]RSN is a protocol for establishing secure communications over the IEEE 802.11 WLAN standard.[/su_note]
The information gathered by attackers through this type of attack is translated into regular hex encoded strings, meaning that no special translation or output format hinders attackers or causes delays.
If the Wi-Fi network is compromised through the technique, cybercriminals may be able to steal login passwords, monitor communications, and perform Man-in-The-Middle (MiTM) attacks.
Which routers are affected?
It is not yet clear which router manufacturers or models are affected by this hack, but many experts believe that it will work against all 802.11i/p/q/r networks with roaming enabled (i.e. against most modern routers).
In action
This attack method requires the PMKID, the key used to establish a connection between a client and an access point. To carry out an attack, the attacker can use a tool such as hcxdumptool (v4.2.0 or later) to request the PMKID from the access point and record the received frame to a file.
$ ./hcxdumptool -o test.pcapng -i wlp39s0f3u4u5 --enable_status
Through the hcxpcaptool tool, the frame output (which will be in pcapng format) can then be converted to a hash format, which is accepted by Hashcat.
$ ./hcxpcaptool -z test.16800 test.pcapng
Using the Hashcat (v4.2.0 or later) the attacker can obtain the WPA PSK (pre-shared key).
$ ./hashcat -m 16800 test.16800 -a 3 -w 3 '? l? l? l? l? l? lt!'
The password of the destination wireless network is revealed, a process that may take time depending on its length and complexity.
We've developed a new attack on WPA/WPA2. There's no more complete 4-way handshake recording required. Here's all details and tools you need: https://t.co/3f5eDXJLAe pic.twitter.com/7bDuc4KH3v
— hashcat (@hashcat) August 4, 2018
WPA3 to the Rescue
The security researcher who made the discovery shared his findings on the Hashcat forum earlier this month. Steube was researching ways to attack the new WPA3 security standard when he came to this conclusion.
WPA3 is the latest update to the Wi-Fi standard, announced in January. WPA3 aims to strengthen user protection, especially when it comes to open Wi-Fi networks and hotspots, which are typically found in public places. The new standard will use personalized data encryption as well as new protections against brute-force techniques used to crack passwords.

