Reaver
๐ก Wireless ยท C
Reaver implements a brute force attack against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/WPA2 passphrases. WPS uses an 8-digit PIN where the last digit is a checksum and the first and second halves are validated separately, reducing the effective keyspace from 100 million to about 11,000 possibilities. Reaver systematically tries PIN combinations against the target access point, typically recovering the passphrase within 4-10 hours depending on the target. It includes features like automatic detection of WPS-enabled access points, session saving and restoring for interrupted attacks, and configurable timing and delay options to handle rate limiting and lockout mechanisms. Reaver is often used alongside Pixiewps for the more efficient Pixie Dust attack against vulnerable WPS implementations that leak enough information to recover the PIN offline in seconds.
Installation
apt (Debian/Ubuntu)
$ sudo apt install reaverfrom source
$ git clone https://github.com/t6x/reaver-wps-fork-t6x.git && cd reaver-wps-fork-t6x/src && ./configure && make && sudo make installUse Cases
- Testing WPS-enabled routers for PIN brute force vulnerabilities
- Recovering WPA/WPA2 passphrases through WPS PIN exploitation
- Auditing wireless networks for WPS misconfiguration and weak implementations
- Combining with Pixiewps for rapid Pixie Dust attacks against vulnerable APs
Tags
Details
- Category
- ๐ก Wireless
- Language
- C
- Repository
- t6x/reaver-wps-fork-t6x
- Platforms
- ๐งlinux
Links
Alternatives & Comparisons
Aircrack-ng
CComplete suite for WiFi network security assessment. Monitoring, attacking, testing, and cracking.
Compare Reaver vs Aircrack-ngBettercap
GoSwiss army knife for WiFi, Bluetooth, and ethernet network recon and MITM. Scriptable with JS.
Compare Reaver vs BettercapWifite2
PythonAutomated wireless attack tool. Wraps aircrack-ng, reaver, and hashcat for streamlined WiFi auditing.
Compare Reaver vs Wifite2Pixiewps
CWPS offline brute force. Exploits weak random number generation in WPS implementations to recover PINs in seconds.
Compare Reaver vs Pixiewpsmdk4
C802.11 protocol exploitation toolkit. Authentication floods, beacon floods, deauth attacks, and SSID fuzzing for wireless testing.
Compare Reaver vs mdk4More in Wireless
Aircrack-ng
CComplete suite for WiFi network security assessment. Monitoring, attacking, testing, and cracking.
Bettercap
GoSwiss army knife for WiFi, Bluetooth, and ethernet network recon and MITM. Scriptable with JS.
Wifite2
PythonAutomated wireless attack tool. Wraps aircrack-ng, reaver, and hashcat for streamlined WiFi auditing.
Kismet
C++Wireless network detector, sniffer, wardriving tool, and IDS. WiFi, Bluetooth, Zigbee, and more.
Flipper Zero Firmware
CCustom firmware for Flipper Zero. Sub-GHz, RFID, NFC, infrared, and GPIO hacking multi-tool.
Fluxion
ShellWPA security auditing tool that uses social engineering for handshake capture via evil twin attacks.