After cracking the PIN code and password of the WPS wireless router under BT5, the method is still very simple, but the time consumption is also a little longer. It has been running from, i'm lucky. 1. Adjust the wireless network card to the Monitor mode so that you can Monitor the traffic of the wireless network card. The specific method is airmon-ng start wlan0. Then run the ifconfig command to find the mon0 device, which indicates that the setting is successful. 2. download and install the reaver software. 3. Run the wash-I mon0 command to find the vrouters that have enabled the WPS function. Of course, if you do not have this command, you can also use the airdump-ng mon0. display in the vro that comes with BT5. If the wps standard appears, it will be correct. Www.2cto.com 4. select a vro with WPS (the signal must be good, and it should be at least-75 ), run the reaver-I mon0-B MAC-vv command. MAC indicates the MAC address of the router displayed in step 3. -Vv is two v, not w. In this way, the reaver software starts to work. Try PIN codes one by one. First, the first four digits of the PIN code are changed. When the first four digits come out, the first 90% digits are successful, and the last three digits are coming soon. Of course, in theory, the possibility of PIN code is 10 ^ 4 + 10 ^ 3 = 11000, so Test 3 PIN codes per second based on the general signal, it will take 9.2 hours to complete all the traversal. So the average use time is 4.6 hours, so it depends on luck .. Of course, as long as the time is enough and the signal is good, the WPS password must be able to be cracked... Author guoliang