Evil Twin
1 min readArticle
in WPA\WPA2 Enterprise there isn't a key or password to connect to the network the way users connect is via a unique username and password for every user that is associated with a RADIUS server. also in coffee shops or malls, there's a captive portal standard that when connecting to a network the user will have a pop-up window that asks him to enter credentials to hack these types of networks there is a solution, and its called Evil Twin attack and it's like its sounds a twin for the target network with the same SSID the way that is work is to disconnect the clients from the real AP continuously and forcing them to connect for our AP (because the SSID is the same the device will connect automatically) besides that captive portal are customizable web pages which means that we can use the same attack on all types of networks no matter the encryption and we should be creative like to hack a personal home router with this method you can do a pop-up window for firmware upgrade when the client write down the password “accepts the agreement” and click “upgrade” which will send us the password in cleartext. I’ll attach some photos below to demonstrate.
to do. those things there are 5 different ways(WiFi-Pineapple, RADIUS authentication, Captive portal dynamically, captive portals with WifiPhisher, captive portals with Fluxion) we will explain all of them here and the difference between them.
techzonesite.comUnlock Your IT Potential