A tester runs hcxdumptool against a WPA2-PSK access point and captures a PMKID from a single management frame exchange, without requiring any connected client to complete a four-way handshake. The tester then feeds the captured hash into hashcat mode 16800 for offline cracking. What attack technique is being used?
- AKARMA attack
- BWPS PIN brute-force attack
- CPMKID attack
- DEvil twin attack
Show answer & explanationAnswer & explanation
Correct answer: C. PMKID attack
The PMKID attack captures the Pairwise Master Key Identifier directly from the AP's first EAPOL frame (often sent even without a connected client), enabling offline cracking with hashcat mode 16800, and does not require capturing a full four-way handshake or client de-authentication. WPS PIN brute-force targets the WPS protocol's PIN exchange, evil twin creates a rogue AP for credential harvesting, and KARMA responds to client probe requests to lure connections.
Why the other options are wrong
- A. A KARMA attack responds to client probe requests for known SSIDs to lure automatic connections.
- B. WPS PIN brute-force attacks the WPS registrar PIN exchange, an entirely different protocol weakness.
- D. An evil twin attack sets up a rogue access point to trick clients into connecting and revealing credentials.
PMKID Attack
A WPA2-PSK attack that captures the Pairwise Master Key Identifier (PMKID) from a single frame sent by the access point, allowing offline password cracking without a full four-way handshake or client interaction.
- Captured with hcxdumptool, cracked with hashcat mode 16800 (or 22000 for the unified format)
- Does not require a connected client or deauthentication attack
- Only works against APs that include the PMKID in the first EAPOL message
Memory trick: PMKID: 'Peek at the Master Key ID' in one quiet frame