Skip to main content

Overview

WPS (Wi-Fi Protected Setup) PIN is an 8-digit code split into two 4-digit halves, verified independently. This design flaw reduces the keyspace from 10⁸ to ~11,000 combinations, making brute force feasible. Pixie Dust exploits weak nonce generation in some chipsets to recover the PIN offline in seconds.

Tools


1. Enable Monitor Mode


2. Enumerate WPS-Enabled Networks

Key output columns: Target APs with Lck: No.

3. Pixie Dust Attack

Offline attack — recovers PIN from weak nonces. Fast (seconds on vulnerable chipsets). With reaver:
With bully:
-K 1 / -d = Pixie Dust mode. If successful, outputs WPS PIN and WPA passphrase.

4. WPS PIN Brute Force

Online attack — tries all PIN combinations. Takes 4–10 hours on non-locked APs. With reaver:
With bully:
Resume interrupted session (reaver):
Session state saved in /etc/reaver/<BSSID>.wpc.

5. Tune for Rate Limiting / Lockouts


6. Known Vulnerable Chipsets (Pixie Dust)

Chipsets with weak nonce generation:
  • Ralink (RT2860, RT3070, RT5370)
  • Realtek (RTL8188)
  • Broadcom (early firmware)
  • Some Atheros implementations
Check with PixieWPS compatibility list if Pixie Dust fails.

Mitigation Reference


Always run wash first. Attacking a locked AP (Lck: Yes) wastes time — wait for lockout to reset or target a different AP.
Authorized environments only. WPS attacks against networks you don’t own or have explicit permission to test are illegal.