CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

During a wireless assessment, a tester identifies an access point with WPS enabled and wants to determine whether it is vulnerable to an offline PIN brute-force attack that could ultimately recover the WPA2 passphrase. Which tool is specifically designed to perform this WPS PIN attack?

  1. AWifite
  2. BKismet
  3. CReaver
  4. DAircrack-ng
Show answer & explanation

Correct answer: C. Reaver

Reaver is purpose-built to exploit weaknesses in the WPS PIN exchange protocol, systematically brute-forcing the eight-digit PIN to recover the WPA/WPA2 passphrase. Kismet is a passive wireless detection tool, Aircrack-ng targets WEP/WPA handshake cracking rather than WPS PINs, and Wifite is an automation wrapper that may call Reaver but is not the underlying WPS attack engine itself.

Why the other options are wrong

  • A. Wifite automates multiple wireless attacks by invoking other tools like Reaver.
  • B. Kismet passively detects and monitors wireless networks; it does not attack WPS.
  • D. Aircrack-ng focuses on capturing and cracking WEP/WPA handshakes, not WPS PINs.

Reaver (WPS Attack Tool)

A tool that exploits a design flaw in WiFi Protected Setup (WPS) by brute-forcing the 8-digit PIN in halves, ultimately recovering the WPA/WPA2 passphrase.

  • Targets WPS-enabled routers
  • Exploits reduced keyspace due to PIN checksum design flaw
  • Often paired with monitor-mode interfaces set up via airmon-ng

Memory trick: Reaver 'reaps' the WPS PIN, one half at a time

More Vulnerability Discovery and Analysis questions