GitHub - armourinfosec/Wireless-Security-and-WiFi-Penetration-Testing
GitHub - armourinfosec/Wireless-Security-and-WiFi-Penetration-Testing
分类 安全 / 安全知识库 预判分类 网络安全


网站介绍
该GitHub仓库提供了一套开放式、动手实践的无线安全与WiFi渗透测试学习笔记,内容涵盖802.11协议、WEP/WPA/WPA2/WPA3加密机制以及aircrack-ng等工具的使用,以CC BY 4.0许可发布,适合安全爱好者和从业人员学习参考。
备注说明

Wireless Security & WiFi Penetration Testing

> A one-month, lab-driven curriculum that takes a learner from wireless fundamentals to enterprise Wi-Fi penetration testing — 802.11 standards and encryption, monitor-mode capture, reconnaissance and traffic analysis, WEP/WPA/WPA2 cracking, WPA3 and TKIP attacks, rogue access points and wireless MITM, and enterprise (EAP/RADIUS) assessment with professional reporting. Curriculum home: Vault Catalog ---

Course Information

| Property | Value | |----------|-------| | Course Title | Wireless Security & WiFi Penetration Testing | | Folder | Wireless-Security-and-WiFi-Penetration-Testing/ | | Tag | Wireless Security | | Slug | wifi-pentest | | Level | Advanced | | Duration | 1 Month (4 Weeks · ~30 Hours) | | Focus | Wireless Penetration Testing | | Reference Platform | Kali Linux · injection-capable adapters (Atheros AR9271 · Ralink RT3070) | | Modules | 14 | | Delivery | Self-paced notes + hands-on labs | | Language | English | > [!NOTE] > What this course is > A study-and-practice track built as an Obsidian knowledge base. Each module is a folder with its own Readme hub and a set of single-topic notes containing tagged, copy-ready command snippets. It is designed to be read in order but is fully cross-linked for reference use. ---

Course Description

Master wireless security testing and Wi-Fi penetration testing end to end: 802.11 standards and frame types, encryption and authentication (WEP, WPA/TKIP, WPA2/CCMP, WPA3), adapter setup for monitor mode and packet injection, reconnaissance and traffic analysis, security-control bypass, denial-of-service, WEP cracking, Chop-Chop and packet-replay attacks, the Caffe Latte client-side attack, WPA/WPA2 handshake and PMKID cracking, Cowpatty and precomputed-table attacks, advanced WPA-TKIP and WPA3 (KRACK/Dragonblood) attacks, rogue access points and wireless MITM — then apply those skills to enterprise WPA (EAP/RADIUS) assessment, wireless hardening, and penetration-test reporting. The program is delivered through reproducible, hands-on labs against equipment you own and control, so every technique is paired with a working capture, attack, or configuration you can build, break, and defend. > [!WARNING] > Authorized testing only > Every technique here is documented for education, detection, and defense. Wireless attacks — deauthentication, jamming, rogue access points, handshake capture, and key cracking — are illegal against networks you do not own or lack explicit written permission to assess. Practice only in your own isolated RF lab, a CTF, or a sanctioned engagement. ---

Overview

The Wireless Security & WiFi Penetration Testing program provides practical, assessment-ready skills across wireless reconnaissance, attack, and defense. It is designed for ethical hackers, penetration testers, red-team operators, and wireless security analysts, and progresses from 802.11 fundamentals to advanced enterprise attacks. By the end of the course, students will be able to:
  • Configure wireless adapters for monitor mode and packet injection
  • Discover hidden SSIDs and enumerate wireless infrastructure
  • Perform wireless DoS and deauthentication attacks
  • Crack WEP encryption using multiple attack techniques
  • Capture and crack WPA/WPA2 handshakes and PMKIDs
  • Deploy evil-twin and rogue access-point attacks
  • Conduct wireless Man-in-the-Middle attacks
  • Perform advanced WPA/TKIP and WPA3 exploitation
  • Assess enterprise WPA (EAP/RADIUS) deployments
  • Provide wireless hardening and remediation recommendations
> [!TIP] > Offense and defense are taught together > Every attack module pairs the exploit with its detection and mitigation — deauth floods with 802.11w/management-frame protection, rogue APs with WIDS, weak PSKs with policy — so the skills transfer directly to defending the same networks. ---

Learning Path

The 14 modules are sequenced into four progressive phases. Complete each phase before advancing; later attack and enterprise modules assume the fundamentals and a capture-capable lab from earlier phases.
text
Phase 1  Fundamentals ....... Wireless Networks · Encryption & Authentication · Adapters
Phase 2  Recon & Bypass ..... Security Measures & Bypass · Reconnaissance & Traffic Analysis
Phase 3  Attacks ............ DoS · MITM/Rogue APs · WEP · Chop-Chop · Caffe Latte
                              WPA/WPA2 · Cowpatty · Advanced WPA-TKIP/WPA3
Phase 4  Enterprise ......... Enterprise WPA (EAP/RADIUS) · Hardening · Reporting
mermaid
flowchart LR
    A[Phase 1<br/>Fundamentals] --> B[Phase 2<br/>Recon & Bypass]
    B --> C[Phase 3<br/>Attacks]
    C --> D[Phase 4<br/>Enterprise & Reporting]
> [!IMPORTANT] > Prerequisite chaining > The attack phases assume a capture-capable lab from Phase 1 and the discovery skills from Phase 2. Attempting a WPA/WPA2 handshake crack or an evil-twin attack without a monito...
获取时间 2026-08-07T16:12:06+00:00
本网址已被浏览 38 次
关键词 无线安全 WiFi渗透测试 802.11 WEP WPA WPA2 WPA3 aircrack-ng
小标签 无线安全 渗透测试 学习笔记 开源
暂无截图,待自动生成。
头像
暂无评论,快来抢沙发吧!