Overview
WPS (Wi-Fi Protected Setup) PIN is an 8-digit code split into two 4-digit halves, verified independently. This design flaw reduces the keyspace from 10⁸ to ~11,000 combinations, making brute force feasible. Pixie Dust exploits weak nonce generation in some chipsets to recover the PIN offline in seconds.Tools
1. Enable Monitor Mode
2. Enumerate WPS-Enabled Networks
Target APs with
Lck: No.
3. Pixie Dust Attack
Offline attack — recovers PIN from weak nonces. Fast (seconds on vulnerable chipsets). With reaver:-K 1 / -d = Pixie Dust mode.
If successful, outputs WPS PIN and WPA passphrase.
4. WPS PIN Brute Force
Online attack — tries all PIN combinations. Takes 4–10 hours on non-locked APs. With reaver:/etc/reaver/<BSSID>.wpc.
5. Tune for Rate Limiting / Lockouts
6. Known Vulnerable Chipsets (Pixie Dust)
Chipsets with weak nonce generation:- Ralink (RT2860, RT3070, RT5370)
- Realtek (RTL8188)
- Broadcom (early firmware)
- Some Atheros implementations
Mitigation Reference
Always run
wash first. Attacking a locked AP (Lck: Yes) wastes time — wait for lockout to reset or target a different AP.