29 ago 2020

Fluxion - Set Up Fake AP, Fake DNS, And Create Captive Portal To Trick Users Into Giving You Their Password





Fluxion is a security auditing and social-engineering research tool. It is a remake of linset by vk496 with (hopefully) less bugs and more functionality. The script attempts to retrieve the WPA/WPA2 key from a target access point by means of a social engineering (phishing) attack. It's compatible with the latest release of Kali (rolling). Fluxion's attacks' setup is mostly manual, but experimental auto-mode handles some of the attacks' setup parameters. Read the FAQ before requesting issues.
If you need quick help, fluxion is also avaible on gitter. You can talk with us on Gitter or on Discord.

Installation
Read here before you do the following steps.
Download the latest revision
git clone --recursive git@github.com:FluxionNetwork/fluxion.git
Switch to tool's directory
cd fluxion 
Run fluxion (missing dependencies will be auto-installed)
./fluxion.sh
Fluxion is also available in arch
cd bin/arch
makepkg
or using the blackarch repo
pacman -S fluxion

Changelog
Fluxion gets weekly updates with new features, improvements, and bugfixes. Be sure to check out the changelog here.

How it works
  • Scan for a target wireless network.
  • Launch the Handshake Snooper attack.
  • Capture a handshake (necessary for password verification).
  • Launch Captive Portal attack.
  • Spawns a rogue (fake) AP, imitating the original access point.
  • Spawns a DNS server, redirecting all requests to the attacker's host running the captive portal.
  • Spawns a web server, serving the captive portal which prompts users for their WPA/WPA2 key.
  • Spawns a jammer, deauthenticating all clients from original AP and lureing them to the rogue AP.
  • All authentication attempts at the captive portal are checked against the handshake file captured earlier.
  • The attack will automatically terminate once a correct key has been submitted.
  • The key will be logged and clients will be allowed to reconnect to the target access point.
  • For a guide to the Captive Portal attack, read the Captive Portal attack guide

Requirements
A Linux-based operating system. We recommend Kali Linux 2 or Kali rolling. Kali 2 & rolling support the latest aircrack-ng versions. An external wifi card is recommended.

Related work
For development I use vim and tmux. Here are my dotfiles

Credits
  1. l3op - contributor
  2. dlinkproto - contributor
  3. vk496 - developer of linset
  4. Derv82 - @Wifite/2
  5. Princeofguilty - @webpages and @buteforce
  6. Photos for wiki @http://www.kalitutorials.net
  7. Ons Ali @wallpaper
  8. PappleTec @sites
  9. MPX4132 - Fluxion V3

Disclaimer
  • Authors do not own the logos under the /attacks/Captive Portal/sites/ directory. Copyright Disclaimer Under Section 107 of the Copyright Act 1976, allowance is made for "fair use" for purposes such as criticism, comment, news reporting, teaching, scholarship, and research.
  • The usage of Fluxion for attacking infrastructures without prior mutual consent could be considered an illegal activity, and is highly discouraged by its authors/developers. It is the end user's responsibility to obey all applicable local, state and federal laws. Authors assume no liability and are not responsible for any misuse or damage caused by this program.

Note
  • Beware of sites pretending to be related with the Fluxion Project. These may be delivering malware.
  • Fluxion DOES NOT WORK on Linux Subsystem For Windows 10, because the subsystem doesn't allow access to network interfaces. Any Issue regarding the same would be Closed Immediately

Links
Fluxion website: https://fluxionnetwork.github.io/fluxion/
Discord: https://discordapp.com/invite/G43gptk
Gitter: https://gitter.im/FluxionNetwork/Lobby




Related posts
  1. Pentest Tools Bluekeep
  2. Hacking Tools 2019
  3. Pentest Tools Website
  4. Beginner Hacker Tools
  5. How To Hack
  6. Android Hack Tools Github
  7. Best Pentesting Tools 2018
  8. Hacker Hardware Tools
  9. Hacker Tools Github
  10. Hacker Tools For Pc
  11. Hacking Tools Software
  12. Usb Pentest Tools
  13. Hacking Tools Software
  14. Hacker Tools 2019
  15. World No 1 Hacker Software
  16. Pentest Tools Find Subdomains
  17. Hacking Tools For Mac
  18. Hacker Tools Free
  19. Hacking Tools For Beginners
  20. Hacking Apps
  21. Hacking Tools For Games
  22. Hacker Tools Mac
  23. Hacker Tool Kit
  24. Computer Hacker
  25. Pentest Tools Github
  26. Hacker Tools Windows
  27. Hacks And Tools
  28. How To Make Hacking Tools
  29. Hacking Tools Kit
  30. Hackers Toolbox
  31. Pentest Tools List
  32. Hacking Tools Download
  33. Hack Tools Download
  34. Pentest Box Tools Download
  35. Pentest Tools
  36. Pentest Tools Windows
  37. Ethical Hacker Tools
  38. Hack Tool Apk
  39. Underground Hacker Sites
  40. Hacker Tool Kit
  41. Pentest Tools Android
  42. Underground Hacker Sites
  43. Pentest Automation Tools
  44. Hack Tools For Pc
  45. Hacker Hardware Tools
  46. Hack Tools Online
  47. Tools 4 Hack
  48. Ethical Hacker Tools
  49. Free Pentest Tools For Windows
  50. Free Pentest Tools For Windows
  51. Hacking Tools 2019
  52. Hacking Tools Kit
  53. Kik Hack Tools
  54. Android Hack Tools Github
  55. Pentest Tools Website Vulnerability
  56. Pentest Tools Website
  57. Black Hat Hacker Tools
  58. Hacking Tools For Mac
  59. Hacker Techniques Tools And Incident Handling
  60. Hacker Tools Windows
  61. Tools For Hacker
  62. Pentest Tools Open Source
  63. Hacking Tools 2020
  64. Hacker Tools Free Download
  65. Hacker Tools Apk Download
  66. Hacker Tools For Mac
  67. Hacking Tools 2019
  68. Hacking Tools Online
  69. Hacking Tools For Beginners
  70. Pentest Tools Linux
  71. Hacking Tools Github
  72. Pentest Box Tools Download
  73. Hacker Tools Windows
  74. Hacks And Tools
  75. Hacker Tools Linux
  76. Hacker Tools Software
  77. Pentest Tools For Mac
  78. Black Hat Hacker Tools
  79. Hacker Tools
  80. Hacking Tools Pc
  81. Pentest Tools List
  82. Pentest Box Tools Download
  83. Pentest Tools Website
  84. Beginner Hacker Tools
  85. Free Pentest Tools For Windows
  86. Hack Tools For Mac
  87. Hacker Tools Free Download
  88. Hacking App
  89. Hacker Search Tools
  90. Pentest Tools For Android
  91. Pentest Tools For Mac
  92. Hack Tools 2019
  93. Beginner Hacker Tools
  94. Hack Tools
  95. Pentest Tools Android
  96. Pentest Tools For Windows
  97. Hack Tools For Games
  98. Hacker Tools Github
  99. Hack Tools Github
  100. Hacker Tools For Pc
  101. Tools Used For Hacking
  102. Hack Apps
  103. Underground Hacker Sites
  104. Hacker Tools
  105. Pentest Tools Github
  106. Hack Tools
  107. What Are Hacking Tools
  108. Hacking Tools And Software
  109. Pentest Tools Find Subdomains
  110. Blackhat Hacker Tools

Nessun commento: