百科.dev
全部条目AI 编程趋势榜开源项目技术资讯提交条目
登录
< 返回工具列表
R

reaver-wps-fork-t6x

> 编程语言
开源

概述 Reaver 实施了针对 Wifi Protected Setup (WPS) 注册器 PIN 的暴力攻击,以恢复 WPA/WPA2 密码,从而破解 WPA/WPA2 密码。

2.0K stars0 点赞0 次浏览
访问官网GitHub

工具介绍

概述 Reaver 实施了针对 Wifi Protected Setup (WPS) 注册器 PIN 的暴力攻击,以恢复 WPA/WPA2 密码,从而破解 WPA/WPA2 密码。

Overview

Reaver implements a brute force attack against Wifi Protected Setup (WPS) registrar PINs in order to recover WPA/WPA2 passphrases, as described in Brute forcing Wi-Fi Protected Setup When poor design meets poor implementation. by Stefan Viehböck.
Reaver has been designed to be a robust and practical attack against Wi-Fi Protected Setup (WPS) registrar PINs in order to recover WPA/WPA2 passphrases and has been tested against a wide variety of access points and WPS implementations.
Depending on the target's Access Point (AP), to recover the plain text WPA/WPA2 passphrase the average amount of time for the transitional online brute force method is between 4-10 hours. In practice, it will generally take half this time to guess the correct WPS pin and recover the passphrase. When using the offline attack, if the AP is vulnerable, it may take only a matter of seconds to minutes.

The first version of reaver-wps (reaver 1.0) was created by Craig Heffner in 2011.
reaver-wps-fork-t6x version 1.6.x is a community forked version which includes various bug fixes, new features and additional attack method (such as the offline Pixie Dust attack).

  • The original Reaver (version 1.0 to 1.4) can be found in google code archives.
  • The discontinued reaver-wps-fork-t6x community edition, reaver version 1.5.3, which includes the Pixie Dust attack, is now the old-master branch from this repository.
  • The latest revison of reaver-wps-fork-t6x community edition is the master branch from this repository.
    Reaver versioning was updated to 1.6.x in order to identify the new cycle.
    All stable relases since the first beta version of reaver 1.6 can be downloaded from our Releases page.
  • More information about the Pixie Dust attack (including which APs are vulnerable) can be found in pixiewps repository, pixie dust thread (in Kali forum) & Dominique Bongard's full disclosure

Requirements

Build-time dependencies

  • libpcap-dev
  • build-essential

Optional build-time dependencies

in case your kernel doesn't support wext extensions (which is unfortunately the case on most modern distros), the included code to switch wireless channels won't work. you can still either switch the channel manually before running reaver/wash without using the channel options, or build against one of the 2 libnl implementations below.

  • libnl-3-dev libnl-genl-3-dev
  • libnl-tiny

then use either ./configure --enable-libnl3 or --enable-libnl-tiny.

Runtime-time dependencies

  • pixiewps (optional, required for pixiedust attack)
  • aircrack-ng (optional, though recommended)

Example

sudo apt -y install build-essential libpcap-dev aircrack-ng pixiewps

The example uses Kali Linux as the Operating System (OS) as pixiewps is included.

You must already have Wiire's Pixiewps installed to perform a pixie dust attack, latest version can be found in its official github repository.


Setup

Download

git clone https://github.com/t6x/reaver-wps-fork-t6x

or

wget https://github.com/t6x/reaver-wps-fork-t6x/archive/master.zip && unzip master.zip

Locate the shell

cd reaver-wps-fork-t6x*
cd src

Compile

./configure
make

Install

sudo make install


Reaver Usage

…

Options description and examples of use can be found in the Readme from Craig Heffner. Here comes a description of the new options introduced since then:

-K or -Z // --pixie-dust

The -K and -Z option perform the offline attack, Pixie Dust (pixiewps), by automatically passing the PKE, PKR, E-Hash1, E-Hash2, E-Nonce and Authkey variables. pixiewps will then try to attack Ralink, Broadcom and Realtek detected chipset. Special note: If you are attacking a Realtek AP, do NOT use small DH Keys (-S) option. User will have to execute reaver with the cracked PIN (option -p) to get the WPA pass-phrase. This is a temporary solution and an option to do a full attack will be implemented soon

-p with arbitrary string // --pin=

See our wiki: Introducing a new way to crack WPS: Option p with an Arbitrary String

Wash Usage

…

A detailed description of the options with concrete syntax examples can be found in Craig Heffner's wash readme.
About the new options and features:

-a // --all

The option -a of Wash will list all access points, including those without WPS enabled.

-j // --json

The extended WPS information (serial, model...) from the AP probe answer will be printed in the terminal (in json format)

"Vendor" column

Wash now displays the manufacturer of the wifi chipset from the Acces Points in order to know if they are vulnerable to pixie dust attack.

Stdout can be piped

Notice that wash output can be piped into other commands. For more information see the wiki article Everything about the new options from wash

Acknowledgements

Contribution

Creator of reaver-wps-fork-t6x "community edition": t6x

Main developer since version 1.6b: rofl0r

Modifications made by: t6_x, DataHead, Soxrok2212, Wiire, AAnarchYY, kib0rg, KokoSoft, rofl0r, horrorho, binarymaster, Ǹotaz, Adde88, feitoi

Some ideas made by: nuroo, kcdtv

Bug fixes made by: alxchk, USUARIONUEVO, ldm314, vk496, falsovsky, rofl0r, xhebox

Special Thanks

  • Soxrok2212 for all work done to help in the development of tools
  • Wiire for developing Pixiewps
  • Craig Heffner for creating Reaver and for the creation of default pin generators (D-Link, Belkin) - http://www.devttys0.com/
  • Dominique Bongard for discovering the Pixie Dust attack.

GitHub Issues· 0 开放

在 GitHub 查看全部

暂无开放 Issues,或尚未同步最近议题。

核心特点

  • •The original Reaver (version 1.0 to 1.4) can be found in google code archives.
  • •The discontinued reaver-wps-fork-t6x community edition, reaver version 1.5.3, which includes the Pixie Dust attack, is now the old-master branch from this repository.
  • •The latest revison of reaver-wps-fork-t6x community edition is the master branch from this repository.
  • •More information about the Pixie Dust attack (including which APs are vulnerable) can be found in pixiewps repository,
  • •libpcap-dev
  • •build-essential
  • •libnl-3-dev libnl-genl-3-dev
  • •libnl-tiny
  • •pixiewps (optional, required for pixiedust attack)
  • •aircrack-ng (optional, though recommended)

> 标签

C

暂无评论,来聊聊你的看法吧

> 工具信息

发布日期2026年8月1日
最后更新2026年9月17日
分类编程语言
定价开源

> 相关工具

T
TypeScript
JavaScript 的超集,为前端与全栈提供静态类型
P
Python
通用编程语言,广泛用于 Web、数据与 AI
G
Go
Google 推出的简洁高效系统语言