Page 1 of 3 123 LastLast
Results 1 to 10 of 28

Thread: captive portal fishing

  1. #1
    Senior Member LHYX1's Avatar
    Join Date
    Sep 2010
    Location
    Belgium
    Posts
    127

    Default captive portal fishing

    Hello everybody

    I have seen many people crack WIFI and set up fake AP's but I never have seen something to hack captive portals.
    So I created a little script

    My script will set up a rogue AP for you and it will spoof all dns requests to your evil http server.
    The essid should be similar to the one of the captive portal. (you could deauth clents and let them connect to you ofcourse )
    Your evil http server should have an html page running that looks exactly like the login page of the captive portal that you like to attack.
    Then when a user types his credentials some evil php code will log them in a txt file.

    You can download my script and the php, html,... here

    There is an example html page included. If you like to build your own page please make sure to add the reference to the php file in the action="" option of the <form> tag.
    Also give your login and password input tag the same id="".

    And set the right file permission on the php file and the txt file ofcourse.
    (script requires dhcpd3 to be installed)

    (This is for educational purpose only ofcourse)
    ps: For some reason I couldn't post in the how to section so please move my thread there.
    Last edited by LHYX1; 12-28-2011 at 03:33 PM.
    (\ /)
    ( . .)
    c(")(")

    This is bunny.
    Copy and paste bunny into your signature to help him gain world domination.

  2. #2
    Good friend of the forums zimmaro's Avatar
    Join Date
    Mar 2010
    Location
    milano
    Posts
    407

    Default Re: captive portal fishing

    hi, LHYNX1
    It's official: "You are my personal Santa-Claus")
    Many, many thanks for your "gifts-work"
    I'm testing on bt5r1 (vbox) + alpha & awuso36h worked great (using your "" "index" "")
    I made another "try changing the bait angling ..."
    ps: I'm allowed to do a little screenshot:
    http://imageshack.us/f/51/lhynx1captiveportalfish.png/

    thanks again ............. by the Zimmaro g0at-brain

  3. #3
    Member melissabubble's Avatar
    Join Date
    Aug 2011
    Location
    c:\
    Posts
    85

    Default Re: captive portal fishing

    hey LHYNX1, do you need to change the subnet and netmask to what my current subnet and netmask are, or do I leave it the way it is in your script?

  4. #4
    Senior Member LHYX1's Avatar
    Join Date
    Sep 2010
    Location
    Belgium
    Posts
    127

    Default Re: captive portal fishing

    @zimmaro hohohoho
    Take as many screenshots as you like.

    @melissabubble you can just leave it this way. You basicly create a new network for your rogue AP so it doesn't matter wat subnet you use.
    (\ /)
    ( . .)
    c(")(")

    This is bunny.
    Copy and paste bunny into your signature to help him gain world domination.

  5. #5
    Senior Member LHYX1's Avatar
    Join Date
    Sep 2010
    Location
    Belgium
    Posts
    127

    Default Re: captive portal fishing

    @zimmaro hohohoho
    Take as many screenshots as you like.

    @melissabubble you can just leave it this way. You basicly create a new network for your rogue AP so it doesn't matter wat subnet you use.
    (\ /)
    ( . .)
    c(")(")

    This is bunny.
    Copy and paste bunny into your signature to help him gain world domination.

  6. #6
    Just burned his ISO
    Join Date
    Jan 2012
    Posts
    7

    Smile Re : captive portal fishing

    HI I am a noob! The wifi broadcast works but I can't get the phishing page up on the client. Could someone please explain to me how to get the phishing page working and the phished logs.

  7. #7
    Just burned his ISO
    Join Date
    Apr 2011
    Posts
    10

    Default Riferimento: Re: captive portal fishing

    LHYX1: thanks a lot for your script! :-))))

    zimmaro: waiting for another great video-tutorial on this.. ;-)

  8. #8
    Senior Member LHYX1's Avatar
    Join Date
    Sep 2010
    Location
    Belgium
    Posts
    127

    Default Re: captive portal fishing

    @Hizagashira Glad you like it

    @stick397

    The "fishing" folder and the "index.html" should go into your /var/www/ directory.
    Be sure to set execution permissions on the php file in the fishing directory and write permissions on the "formdata.txt".
    If you don't know how to set file permissions, have a look here: http://www.elated.com/articles/under...g-permissions/
    You can start your apache webserver by typing "service apache2 start" from the terminal.
    Make sure it's running by browsing to 127.0.0.1 with firefox or whatever.

    This should do it
    Last edited by LHYX1; 01-02-2012 at 05:28 PM.
    (\ /)
    ( . .)
    c(")(")

    This is bunny.
    Copy and paste bunny into your signature to help him gain world domination.

  9. #9
    Member melissabubble's Avatar
    Join Date
    Aug 2011
    Location
    c:\
    Posts
    85

    Default Re: captive portal fishing

    Hey LHYX1, noob question?...lol I understand how to change permissions, but change the write permission for who, owner, group, or others?

  10. #10
    Senior Member LHYX1's Avatar
    Join Date
    Sep 2010
    Location
    Belgium
    Posts
    127

    Default Re: captive portal fishing

    @melissabubble Normaly you should set the group to "www-data" I think and then set permissions so that a websurfer can execute your php code and that the php code can write to the "formdata.txt".
    chmod 777 for the txt file and chmod 555 for the php file if I recall it correctly.
    I am not an expert at this either but this is how I did it
    (\ /)
    ( . .)
    c(")(")

    This is bunny.
    Copy and paste bunny into your signature to help him gain world domination.

Page 1 of 3 123 LastLast

Similar Threads

  1. Fake AP and captive Portal
    By CeEe4 in forum OLD Wireless
    Replies: 7
    Last Post: 02-26-2010, 11:49 PM
  2. Rogue AP and Captive Portal
    By CeEe4 in forum OLD Newbie Area
    Replies: 0
    Last Post: 02-03-2010, 04:05 PM
  3. Setup Captive Portal
    By thedon in forum OLD Newbie Area
    Replies: 2
    Last Post: 01-29-2010, 10:32 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •