Wi-Fi Hacking
Wi-Fi security, taken apart one generation at a time, with a lab for every attack and no hardware anywhere. Each module pairs a short piece of theory with one hands-on lab that runs on simulated radios inside a container. The radios are real to every tool you will use: hostapd runs the access point
- 9
- Modules
- 13
- Lectures
- 8
- Hands-on labs
- 4h
- Of material
About this course
Wi-Fi security, taken apart one generation at a time, with a lab for every attack and no hardware anywhere.
Each module pairs a short piece of theory with one hands-on lab that runs on simulated radios inside a container. The radios are real to every tool you will use: hostapd runs the access points, wpasupplicant runs the clients, and aircrack-ng, reaver, pixiewps, hcxtools, hashcat and hostapd-wpe are the same binaries you would use on an engagement. What is missing is the physical radio layer, which means this course teaches protocol attacks, which is where nearly all real Wi-Fi compromise happens.
You will capture a beacon and find a network nobody told you about, recover a WEP key from traffic you provoked the access point into generating, force a four-way handshake and crack it offline, take a WPS PIN apart in seconds using a bug that shipped on real chipsets, stand up an evil twin with a captive portal and watch credentials arrive, downgrade a WPA3 network through the WPA2 leg it still advertises, harvest enterprise credentials with a rogue RADIUS server against a client that does not check certificates, and then sit on the other side and watch a sensor catch all of it.
Every lab is a playground. There are no flags. Each one ends with questions about what you found, in the style of a real assessment: the channel, the BSSID, the passphrase, the PIN, the username that was handed over.
Syllabus
9 modules, 13 lectures, 9 quizzes and 8 hands-on challenges.
Module 0: 802.11 Foundations
The vocabulary every later lab assumes. Theory only, no lab.
- What is actually in the air
- How a client joins, and where the gaps are
- Channels, bands, and why monitor mode exists
- The five generations, in one page
- Why simulated radios teach this properly, and where they stop
1 quiz
Module 1: The Simulated Environment and Monitor Mode
Your radio, monitor mode, and the tools you will use in every later lab.
- The simulated environment, and the tools you will use on it
1 quiz 1 hands-on challenge
Module 2: Open and WEP Networks
Networks with no encryption, and networks whose encryption you can take apart with arithmetic.
- Open networks and WEP
1 quiz 1 hands-on challenge
Module 3: WPA/WPA2 Handshake Capture and Cracking
The four-way handshake, why capturing it is enough, and what deauthentication costs you.
- The four-way handshake, and why capturing it is enough
1 quiz 1 hands-on challenge
Module 4: WPS Attacks
An eight digit PIN, checked in two halves, and a randomness bug that made it worse.
- WPS: a convenience feature with a keyspace problem
1 quiz 1 hands-on challenge
Module 5: Rogue APs, Evil Twins, and Captive Portal Evasion
The attack that does not care which encryption you chose.
- Rogue access points, evil twins, and captive portals
1 quiz 1 hands-on challenge
Module 6: WPA3 and SAE Attacks
What SAE genuinely fixes, and where the practical attack surface moved to.
- WPA3-Personal, SAE, and the transition-mode problem
1 quiz 1 hands-on challenge
Module 7: Enterprise Networks (802.1X / RADIUS)
Per-user authentication, and the one client setting the whole thing rests on.
- Enterprise Wi-Fi, and the one setting that decides whether it works
1 quiz 1 hands-on challenge
Module 8: Detection and Defence (WIDS)
Every attack in this course, seen from the monitoring side, and the ones that leave nothing to see.
- Seeing it from the other side
1 quiz 1 hands-on challenge
9 modules about 4 hoursOpened from your Arena account
Take Wi-Fi Hacking
Create an account to open the lectures and launch this course's labs in the browser.
Create a free account