wifi-wireless

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Wi-Fi / Wireless Security

Wi-Fi / Wireless Security

ACTION REQUIRED(读完后立刻执行)

ACTION REQUIRED (Execute Immediately After Reading)

  1. NOW
    : 读取 precedent-pentest;无线攻击法律风险高,必须书面授权与物理范围
  2. NOW
    : scope 写明目标 SSID/BSSID/场地;禁止扫邻居网络
  3. NEXT
    : 确认适配器监听模式能力
  4. ACT
    : 侦察 → 采集 → 分析(实验室优先)
  1. NOW
    : Read precedent-pentest; Wireless attacks carry high legal risks, written authorization and physical scope are mandatory
  2. NOW
    : Specify target SSID/BSSID/location in the scope; Scanning neighboring networks is prohibited
  3. NEXT
    : Verify adapter monitor mode capability
  4. ACT
    : Reconnaissance → Capture → Analysis (Lab environment preferred)

适用场景

Applicable Scenarios

  • 授权 Wi-Fi 安全评估
  • WPA/WPA2 握手采集与离线评估
  • 流氓 AP / 钓鱼热点检测研究
  • 企业无线隔离与门户安全
  • Authorized Wi-Fi security assessment
  • WPA/WPA2 handshake capture and offline assessment
  • Rogue AP / phishing hotspot detection research
  • Enterprise wireless isolation and portal security

工作流

Workflow

text
□ iwconfig / airmon-ng 进入 monitor(合法环境)
□ airodump-ng 锁定目标 BSSID 频道
□ 握手或 PMKID 采集(仅目标)
□ hashcat/aircrack 离线评估口令策略
□ 报告:加密类型、隔离、门户绕过、建议
text
□ iwconfig / airmon-ng enter monitor mode (authorized environment)
□ airodump-ng lock onto target BSSID channel
□ Handshake or PMKID capture (target only)
□ hashcat/aircrack offline password policy assessment
□ Report: Encryption type, isolation, portal bypass, recommendations

工具链

Toolchain

工具用途
aircrack-ng suite采集/评估
hcxdumptool / hcxtoolsPMKID
hashcat口令评估
Wireshark管理帧分析
ToolPurpose
aircrack-ng suiteCapture/assessment
hcxdumptool / hcxtoolsPMKID
hashcatPassword assessment
WiresharkManagement frame analysis

参考

References

  • references/wireless-lab-rules.md
  • ../pentest-tools/
    ../attack-chain/
    (近源章节)
  • references/wireless-lab-rules.md
  • ../pentest-tools/
    ../attack-chain/
    (close-range section)

路由上下文

Routing Context

上游: MASTER R29
MUST NOT: 未授权 deauth、对非目标客户网络操作
Upstream: MASTER R29
MUST NOT: Unauthorized deauth, operations on non-target customer networks

任务完成自检

Task Completion Checklist

  • 是否严格锁定目标 BSSID?
  • 是否在报告中给出加固建议?
  • Checklist?
  • Is the target BSSID strictly locked?
  • Are hardening recommendations included in the report?
  • Checklist completed?