this post was submitted on 14 Mar 2025
55 points (98.2% liked)

Cybersecurity

6873 readers
155 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 8 comments
sorted by: hot top controversial new old
[–] [email protected] 17 points 2 weeks ago (1 children)

Tl;dr enable protected management frames if you can.

[–] [email protected] 11 points 2 weeks ago

It's the "if you can" part that's holding it back. There's a lot of devices, both clients and WiFi systems, out there that don't support it well.

[–] [email protected] 8 points 2 weeks ago (1 children)
[–] [email protected] 2 points 2 weeks ago (1 children)

How different is this from aircrackng? Based on the description, it sounds like they both accomplish the same thing.

[–] [email protected] 2 points 2 weeks ago (1 children)

Pwnagotchi mainly just does gamified deauth, by default it doesn't do the cracking of the collected pcaps.

Aircrackng can be installed as a plugin, but since it typically runs on rpi zeros it isn't very performant. You'd typically want to move your pcaps to a different machine to do the cracking portion (either using aircrack or hashcat), or use aircrack's entire suite on a more powerful laptop or something like that.

[–] [email protected] 2 points 2 weeks ago (1 children)

Ah ok cool. So pwnagotchi is intended more as a teaching tool or a POC pentest, as opposed to an actual pentest. Am I understanding correctly?

[–] [email protected] 1 points 2 weeks ago (1 children)

Yeah, pretty much. Although I'm sure plenty of people use it for malicious purposes, since it's more convenient than carrying around a laptop, or for building out/competing on the opwngrid.

It's definitely not meant for commercial use, if that's what you're asking.

[–] [email protected] 3 points 2 weeks ago

Less for commercial use, and more for a true pentest of your own network. Well, I guess also for commercial use, for those professional pentesters out there, but I wasn't thinking of them when I asked :/

This whole gamified thing sounds pretty awesome, to be honest, and I'm intrigued.