By hearing every packet, we can later capture the WPA/WPA2 4-way handshake.
There is a small dictionary that comes with aircrack-ng -.
The point is, if you don't get it the first time, have patience and experiment a bit.
We will use the aireplay-ng command to send fake deauth crack packets to our victim client, forcing it to reconnect to the network and hopefully grabbing a handshake in the process.
Dont be a dick.
