PMKID Attack
Definition
A 2018 technique by Jens Steube (hashcat author) that derives the Pairwise Master Key Identifier from a single EAPOL frame the AP advertises, removing the need to capture a client handshake. Hashcat mode -m 16800.
Related terms
- 4-Way Handshake
- The WPA/WPA2 key-establishment exchange between client and AP. Captured frames let an offline dictionary attack recover a weak PSK. WPA3 replaces this...
- BSSID / ESSID
- BSSID is the MAC address of the access point (or virtual AP). ESSID is the human-readable network name broadcast in beacons. Multiple...
- Evil Twin
- A rogue AP broadcasting the same ESSID as a legitimate network at a stronger signal, so clients with cached profiles auto-associate. Often...
- IMSI Catcher
- A rogue base station (commercial: Stingray, Hailstorm, KingFisher; research: USRP plus srsRAN or YateBTS) that impersonates a cellular cell, forces nearby phones...
- KRACK
- Key Reinstallation Attack, CVE-2017-13077, disclosed by Mathy Vanhoef in 2017. By replaying message 3 of the 4-way handshake, the client is forced...
Explained in
- Wireless Network Attacks: WEP, WPA, WPA2, WPA3 and Rogue Access PointsA 2018 technique by Jens Steube (hashcat author) that derives the Pairwise Master Key Identifier from a single EAPOL frame the AP advertises, removing the need...