Install any skill in seconds. Free to start, no credit card required.
Get Started Free →KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT vendors, and the practical limitations of these attacks in modern engagements. Use when assessing legacy supplicants, embedded clients, or vendors with poor patch cadence.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 49% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -58% | 0% |
| case-14 | ✗→✓ | ▲ Improved | 35% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 15% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 37% | 0% |
Two attack families against WPA2 client implementations. Both well-disclosed (KRACK 2017, FragAttacks 2021) and largely patched on modern OSes — but the embedded/IoT long tail keeps them in scope for many engagements.
| Family | Target | Patch Status | |---|---|---| | KRACK | WPA2 supplicants in 4-way handshake / GTK / FT / TDLS | Major OSes patched 2017–2018 | | FragAttacks | Frame fragmentation/aggregation across WPA2/3 | Most stacks patched 2021–2022 |
Probability of success today is high only against:
Modern Win11 / iOS 16+ / Android 13+ / hostapd-2.10 are mitigated.
The 4-way handshake's M3 retransmission causes the supplicant to reinstall the same PTK with reset nonce/replay counters. Frames encrypted under the reused keystream become decryptable.
bash# Vanhoef's official test scripts git clone https://github.com/vanhoefm/krackattacks-scripts cd krackattacks-scripts/krackattack sudo ./krack-test-client.py --interface wlan0 # Tests the supplicant on a connected client
Output identifies which CVE variants the client is vulnerable to.
When successful:
Not a PSK recovery — you don't get the wireless password from KRACK.
FragAttacks abuse 802.11 fragmentation and aggregation to inject frames that mix encrypted and plaintext fragments, or to splice attacker-controlled fragments into legitimate frames.
bashgit clone https://github.com/vanhoefm/fragattacks cd fragattacks sudo ./test-fragattacks.py wlan0 --interface wlan0 # Suite of ~12 tests covering each variant
| CVE | Mechanism | |---|---| | CVE-2020-24588 | A-MSDU spoofing — inject crafted A-MSDU subframes | | CVE-2020-24587 | Mixed-key fragment cache poisoning | | CVE-2020-24586 | Decoupled fragment cache → reuse | | CVE-2020-26139 | Forwarding plaintext frames before authentication | | CVE-2020-26140 | Accepting plaintext frames in protected network |
bash# Rogue AP that drives the test sudo hostapd-mana /tmp/krack_test_ap.conf # Force client to associate (deauth from real AP, or social-engineer) sudo aireplay-ng --deauth 5 -a <real-BSSID> -c <client-MAC> wlan0mon # Run test once associated sudo ./krack-test-client.py --interface wlan0
For each vulnerable CVE:
Other measured skills in the registry, with their headline benchmark lift.