
Learn wireless basics, security protocols, Aircrack-ng setup, and step-by-step methods to uncover and exploit wireless vulnerabilities, including evil twin and social engineering attacks.
Learn foundational wireless concepts, security protocols, and practical penetration testing tools, from antenna basics and wireless frames to WEP, WPA/WPA2, WPA3, hash cracking, and automated attack scripts.
Learn wireless basics and terminologies for penetration testing, including access points, ssids, pre-shared keys, frames and beacons, channels and data rates, monitor mode and promiscuous sniffing, vlan concepts.
Explore wireless security protocols from open authentication to WPA3, covering WEP weaknesses, hidden SSIDs, four way handshake, PMK attacks, and enterprise WPA2 with 802.1X and CCMP.
Learn to set up the aircrack-ng suite in Kali Linux, enable monitor mode with airmon-ng, sniff with airodump-ng, and perform injections with aireplay-ng, plus practical lab setup tips.
Set up wireless pentesting on Kali Linux using a Raspberry Pi; configure monitor mode with iwconfig and airmon-ng, then use airodump-ng for network analysis.
Attack WEP by placing the wireless interface in monitor mode, replaying ARP requests with aireplay-ng, collecting IVs, and cracking the key with aircrack-ng, using Wi-Fi for automation.
Explore how WEP vulnerabilities expose wireless networks in a lab demo using Kali on a Raspberry Pi, monitor mode, ARP manipulation, and aircrack-ng to crack the web key.
Explore attacks on WPA/WPA2 by capturing the handshake and deauthenticating clients, then crack the captured hash with hashcat or aircrack-ng using dictionary or brute-force methods, noting password strength.
Capture the four-way WPA/WPA2 handshake by running airodump-ng on a monitor interface for a bssid on channel 11, then deauthenticate the client with aireplay-ng to trigger and save the handshake.
Crack a WPA/WPA2 handshake in a lab using aircrack-ng with a common.txt word list from Kali, demonstrating handshake capture, dictionary attack, and key discovery.
Explore pmkid attacks against wpa wpa2 psk by capturing the pmkid with hcxdumptool, even without a connected client. Crack the offline hash with hashcat using wordlists or brute-force.
Explore pmkid attack vectors in a hands-on lab, capturing epoll messages and extracting pmkid values from wireless networks, with ethical guidelines and hashcat preparation.
Examine wireless denial of service techniques, including jamming across frequencies and authentication-based access disruption, with practical lab demonstrations and simple scripts for Wi-Fi DDoS testing.
Demonstrate a wireless denial-of-service attack using the Bompai script on a WPA2 network, showing a Kali machine, Raspberry Pi, and Android phone disrupting an access point in monitor mode.
Explore wifi protected setup attacks, comparing push button and pin brute-forcing, distinguishing version 1 and version 2 protections, and previewing lab demonstrations with Wash, Bully, and Riva.
Demonstrates practical wp attacks by using monitor mode, wash to enumerate wp networks, and pin-based tools like river or wp spin connect to attempt brute-force connections.
Explore evil twin attacks and social engineering to lure users to counterfeit access points, capture credentials through credential phishing and splash pages, and test wireless network security.
Explore using Wi-Fi Fisher to create rogue access points and evil twin setups, orchestrate social engineering and phishing campaigns with splash pages, and capture credentials via CLI and GUI workflows.
Welcome to the Ultimate Wireless Penetration Testing / Ethical Hacking course.
Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.
In this course Martin walks students through a step-by-step methodology on how to uncover find and exploit wireless vulnerabilities. The theoretical lectures are being complimented with the relevant lab exercises to reinforce the knowledge. Martin is not just inserting the payload or uses automated scripts but explains each step on finding the vulnerability and why it can be exploited in a certain way. The videos are easy to follow along and replicate. This training is highly recommended for anyone who wants to become a professional Wireless Penetration Tester.
Course outline:
1. Introduction
2. Wireless Basics and Terminologies
3. Wireless Security Protocols
4. Aircrack-NG Suite and setting up
5. Attacking WEP
6. Attacking WPA/WPA2
7. PMKID Attacks
8. DoS Attacks
9. WPS Attacks
10. Evil Twin and Social Engineering Attacks
11. Automate Attacks
12. Advanced Tools
Notes & Disclaimer
In order to replicate the labs, you will need a laptop with a virtual installation of Kali Linux (VMWare, Virtualbox etc.) or a physical machine with Kali or a Raspberry PI with Kali. Additionally, you will need an external Antenna which supports injection. We recommend the Alfa series (e.g. Alfa AC1900 WiFi adapter). Lastly you need an Access Point you own or have permission to attack.