Evil twin / rogue AP¶
1. Context & stakes¶
Clone an AP (SSID/BSSID) to MITM associating clients.
Wi-Fi clients identify an access point by its SSID and roam to the strongest signal, with no mutual authentication on open or PSK networks. An attacker clones the SSID and BSSID with a stronger signal so victims associate to the rogue AP and route all their traffic through it. Captive-portal clones and free-Wi-Fi twins are a staple of credential theft in airports, hotels and conferences.
2. Theory¶
Clients roam by SSID, not BSSID, and many probe for known networks. An attacker raises an AP with the same SSID (often a stronger signal); with karma it answers every probe, so clients auto-associate. Traffic then flows through the attacker (DNS/HTTP MITM, captive portal) - the victim sees the expected name and never notices the BSSID changed.
3. Attack (PoC)¶
- Karma / known-beacon responses
- Captive-portal credential capture, MITM
4. Detection¶
Indicators to watch, and the associated IDS rule (see
netlab-ids).
5. Defense¶
- 802.1X/EAP-TLS with server-cert validation
- WIPS rogue-AP detection
6. Exercise¶
This module is not replayable in the netns/veth lab - it needs real radio hardware. Build a wireless bench you fully own:
- A Wi-Fi adapter that supports monitor mode + injection (e.g. Atheros AR9271, MediaTek MT7612U); enable it with
sudo airmon-ng start wlan0. - A dedicated victim AP you own (a spare router, or a
hostapdsoft-AP) plus a throwaway client - never a third party's network. - Run the bench in a shielded / low-traffic area; attacking any network you do not own is illegal.
7. Further reading¶
- Dai Zovi & Macaulay, KARMA attacks (2005)
- hostapd-wpe, wifiphisher
- RFC 8952 - Captive Portal Architecture