Welcome back in the last Wireless tutorial we talked a little about hacking WPA/WPA2 passwords using brute forcing methods in this tutorial Hack Wi-Fi Networks Without Cracking Wifiphisher. We will talk about hacking WPA/WPA2 networks without using brute force methods by creating a Evil Twin access point mimicking a Wireless access point we can easily trick clients into connecting to it and leak their credentials.
What is Wifiphisher
Wifiphisher is a wireless security tool that mounts automated victim customized phishing attacks against WiFi clients. This allows the attacker to obtain credentials or infect the target machine with malware. This method uses a social engineering attack method that can quickly trick the target into unknowingly handing over there password. Unlike other methods it does not include any brute forcing of any kind. It is an quick and easy way to obtaining credentials from captive portals and third party login pages (e.g. in social networks) or WPA/WPA2 pre-shared keys.
Wifiphisher works on Kali Linux and is licensed under the GPL license.
Scenario
Lets assume that we are testing security of our home network. We have turned off WPS and took all the precautions to safe guard our network against attackers. We have also changed the Password of the network AP to a strong password to prevent brute force attacks. Although there are others who use the same network from other devices who could potentially leak the Wireless password through human error this Wireless attack relies on a little deception and trickery.
Lets assume our network has 1 Access Point that is shared amongst 3 users we could use Wifiphisher to trick the clients into openly and unknowingly handing over their password. Using Social Engineering techniques Wifiphisher can easily create a Evil Twin access point we can trick the clients into reconnecting to the Evil Twin access point.
Installing Wifiphisher
To install Wifiphisher clone the script using git.
In a new terminal use these commands to download and install Wifiphisher.
git clone https://github.com/wifiphisher/wifiphisher.git
cd wifiphisher
sudo python setup.py install
After the script has finished unpacking and installing resources we can start Wifiphisher.
python setup.py build && python setup.py install
Requirments
1x Wireless Interface that supports Managed mode.
1x Wireless INterface that supports Monitor mode.
Kali Linux or Linux Operating System
Wifiphisher
First of all do a scan of near by access points we will be looking for clients connected to the Network.
Start Wifiphisher using the following command.
wifiphisher
Alternately use python bin/wifiphisher from Wifiphishers script location.
python bin/wifiphisher
Specify Wireless Interfaces (Sometimes when starting Wifiphisher it will automatically select what network interfaces to use using the commands below we can specify what interfaces we want to use.)
Lets start first and up a new terminal and go to Wifiphishers download location using cd for example.
cd wifiphisher
Now start wifiphisher replace wlan1, wlan2 with name of your Wireless interfaces.
python bin/wifiphisher -aI wlan1 -jI wlan2
(-aI = ap interface -jI = Jamming interface)
Wifiphisher will now start scanning for wireless Networks. From the Network list choose the target wireless network using up and down keys when you have found the target network press Enter.
What is Wifiphisher
Wifiphisher is a wireless security tool that mounts automated victim customized phishing attacks against WiFi clients. This allows the attacker to obtain credentials or infect the target machine with malware. This method uses a social engineering attack method that can quickly trick the target into unknowingly handing over there password. Unlike other methods it does not include any brute forcing of any kind. It is an quick and easy way to obtaining credentials from captive portals and third party login pages (e.g. in social networks) or WPA/WPA2 pre-shared keys.
Wifiphisher works on Kali Linux and is licensed under the GPL license.
Scenario
Lets assume that we are testing security of our home network. We have turned off WPS and took all the precautions to safe guard our network against attackers. We have also changed the Password of the network AP to a strong password to prevent brute force attacks. Although there are others who use the same network from other devices who could potentially leak the Wireless password through human error this Wireless attack relies on a little deception and trickery.
Lets assume our network has 1 Access Point that is shared amongst 3 users we could use Wifiphisher to trick the clients into openly and unknowingly handing over their password. Using Social Engineering techniques Wifiphisher can easily create a Evil Twin access point we can trick the clients into reconnecting to the Evil Twin access point.
Installing Wifiphisher
To install Wifiphisher clone the script using git.
In a new terminal use these commands to download and install Wifiphisher.
git clone https://github.com/wifiphisher/wifiphisher.git
cd wifiphisher
sudo python setup.py install
After the script has finished unpacking and installing resources we can start Wifiphisher.
python setup.py build && python setup.py install
Requirments
1x Wireless Interface that supports Managed mode.
1x Wireless INterface that supports Monitor mode.
Kali Linux or Linux Operating System
Wifiphisher
First of all do a scan of near by access points we will be looking for clients connected to the Network.
Start Wifiphisher using the following command.
wifiphisher
Alternately use python bin/wifiphisher from Wifiphishers script location.
python bin/wifiphisher
Specify Wireless Interfaces (Sometimes when starting Wifiphisher it will automatically select what network interfaces to use using the commands below we can specify what interfaces we want to use.)
Lets start first and up a new terminal and go to Wifiphishers download location using cd for example.
cd wifiphisher
Now start wifiphisher replace wlan1, wlan2 with name of your Wireless interfaces.
python bin/wifiphisher -aI wlan1 -jI wlan2
(-aI = ap interface -jI = Jamming interface)
Wifiphisher will now start scanning for wireless Networks. From the Network list choose the target wireless network using up and down keys when you have found the target network press Enter.

