一个完整、模块化且可复现的邪恶双子接入点设置,用于防御性安全测试、渗透测试及无线安全研究。
仅用于教育及授权安全测试
本工具提供用于:
严禁非法使用。在大多数司法管辖区,未经授权访问计算机网络属于犯罪行为。使用者须独自承担以下责任:
使用本工具即表示您同意仅在自己拥有或已获明确书面许可的网络上进行测试。
本工具包创建一个模拟合法网络的恶意无线接入点(邪恶双子)。通过创建相同的 SSID 诱使客户端自动连接,从而捕获网络流量,使其误认为是合法网络。
邪恶双子是一种看似合法、实则被设置用于窃听无线通信的欺诈性 Wi-Fi 接入点。该攻击的原理是在目标网络附近部署一个恶意接入点,广播相同的 SSID,诱使设备连接。
您的无线适配器必须支持 AP(接入点)模式。并非所有无线网卡都支持此功能。
以下适配器已知工作良好并支持 AP 模式:
| 芯片组 | 型号示例 | 特性 | 价格范围 |
|---|---|---|---|
| RTL8812AU | Alfa AWUS036ACH, TP-Link Archer T4U | 双频(2.4/5GHz)、高功率、优秀覆盖 | $40-60 |
| RTL8814AU | Alfa AWUS1900, TP-Link Archer T9UH | 四天线、AC1900、长距离 | $60-80 |
| Atheros AR9271 | TP-Link TL-WN722N v1, Alfa AWUS036NHA | 稳定、支持良好、经济实惠 | $20-35 |
| MT7612U | Panda PAU0D, Alfa AWUS036ACM | 双频、兼容性好 | $35-50 |
| RTL8188EU | 各种平价适配器 | 基础、仅2.4GHz、入门级 | $10-20 |
Alfa AWUS036ACH(RTL8812AU)
TP-Link TL-WN722N v1(Atheros AR9271)
Alfa AWUS036ACM(MT7612U)
购买前,请验证适配器是否支持 AP 模式:```bash
iw list | grep -A 10 "Supported interface modes"
### 附加硬件
- **以太网连接**:用于互联网透传(可以是物理或USB以太网适配器)
- **足够的USB电源**:某些高功率适配器可能需要有源USB集线器
- **计算机**:任何运行Linux的笔记本电脑或台式机(推荐:Kali Linux)
---
## 💻 软件需求
### 操作系统
- **推荐**:Kali Linux(2020.1或更高版本)
- **也支持**:
- Debian 10+
- Ubuntu 18.04+
- Fedora 30+
- Arch Linux
- ParrotOS
- BlackArch
### 所需软件包
这些将由 `install_dependencies.sh` 自动安装:
- `hostapd` - 创建接入点
- `dnsmasq` - 提供DHCP和DNS服务
- `iptables` - 配置NAT和防火墙规则
- `iproute2` - 网络接口配置
- `wireless-tools` - 无线管理工具
- `net-tools` - 网络诊断工具
- `iw` - 无线配置工具
- `tcpdump` - 数据包捕获工具
### 权限
- 所有操作都需要root/sudo权限
---
## 📦 安装
### 快速开始```bash
# Clone the repository
git clone https://github.com/yourusername/evil-twin-ap.git
cd evil-twin-ap
# Install dependencies
sudo ./install_dependencies.sh
# Detect your wireless interfaces
sudo ./detect_interface.sh
# Configure your settings (update interface if needed)
nano hostapd.conf # Change SSID, channel, interface
nano dnsmasq.conf # Adjust DHCP settings, interface
# Start the evil twin
sudo ./start_evil_twin.sh
git clone https://github.com/yourusername/evil-twin-ap.git cd evil-twin-ap
#### Step 2: 安装依赖项
安装脚本会自动检测您的 Linux 发行版并安装所需的软件包:```bash
sudo ./install_dependencies.sh
功能:
关键步骤: 在配置之前,检测哪个无线接口支持AP模式:```bash sudo ./detect_interface.sh
该脚本将分析所有无线接口并推荐最佳使用接口。
**示例输出:**```
==========================================
Wireless Interface Detection
==========================================
[INFO] Scanning for wireless interfaces...
[✓] Found 2 wireless interface(s)
═══════════════════════════════════════════
Interface: wlan1
═══════════════════════════════════════════
State: DORMANT
MAC Address: 1a:60:c6:85:87:53
Driver: rtl88XXau
[INFO] Checking capabilities for wlan1...
[✓] Supports AP mode (Access Point) ✓
[✓] Supports Monitor mode ✓
Current Mode: managed
═══════════════════════════════════════════
Interface: wlan0
═══════════════════════════════════════════
State: DOWN
MAC Address: b2:72:bf:bc:31:bd
Driver: iwlwifi
[INFO] Checking capabilities for wlan0...
[✓] Supports AP mode (Access Point) ✓
[✓] Supports Monitor mode ✓
Current Mode: managed
[!] Power management is ON (may cause issues)
==========================================
Summary & Recommendations
==========================================
[✓] Found 2 AP-capable interfaces:
- wlan1
- wlan0
[INFO] Recommendation: Use wlan1 (likely external USB adapter)
[!] wlan0 is usually built-in WiFi - use external adapter if available
[INFO] To update configuration files, run:
sed -i 's/^interface=.*/interface=wlan1/' hostapd.conf
sed -i 's/^interface=.*/interface=wlan1/' dnsmasq.conf
Current Configuration:
hostapd.conf: interface=wlan1
dnsmasq.conf: interface=wlan1
[INFO] After updating, verify with: iw list | grep -A 10 'Supported interface modes'
关键见解:
如果您有多个接口:
安装和接口检测完成后,验证一切是否正常工作:```bash
hostapd -v
dnsmasq -v
iw dev
iw list | grep -A 10 "Supported interface modes"
grep "^interface=" hostapd.conf dnsmasq.conf
---
## ⚙️ 配置
### hostapd.conf - 接入点设置
编辑 `hostapd.conf` 来定制你的邪恶双胞胎:```bash
nano hostapd.conf
需要修改的关键设置:```ini
interface=wlan1
ssid=TestNetwork
channel=6
wpa_passphrase=letitrain2
country_code=US
### dnsmasq.conf - DHCP/DNS 设置
编辑 `dnsmasq.conf` 以自定义网络设置:```bash
nano dnsmasq.conf
关键设置:```ini
interface=wlan1
dhcp-range=192.168.99.10,192.168.99.250,12h
dhcp-option=3,192.168.99.1
server=8.8.8.8 server=8.8.4.4
### 网络配置
**默认设置:**
- **AP IP**: 192.168.99.1
- **子网**: 192.168.99.0/24
- **DHCP范围**: 192.168.99.10 - 192.168.99.250
- **信道**: 6 (2.4GHz)
- **密码**: letitrain2
- **接口**: wlan1 (外部适配器)
---
## 🚀 使用
### 启动 Evil Twin```bash
sudo ./start_evil_twin.sh
发生什么: