hackweb
notes on hacking and technology
IT EN
main menu
user menu
you are not logged in

Evil twin: the malicious twin access point

July 13, 2025 · 1 min read · #network #wifi #rogue-ap

Devices auto-reconnect to known networks by SSID. An evil twin clones the SSID and offers a stronger signal: clients pick it.

The flow

The attacker creates an AP with an identical SSID ("Airport_WiFi"), often combined with deauth to knock clients off the real AP. Once connected, a fake captive portal asks for the corporate WiFi password or email credentials.

hostapd + dnsmasq + a cloned login page

Defence

Corporate networks with 802.1X/EAP and server-certificate validation (the client verifies the AP, not just the other way). Disable auto-reconnect to open networks. WIDS to detect rogue APs. Distrust captive portals asking for passwords.


« back to home

latest posts
 
your IP address:
216.73.216.108
visitor #0
MOTD:
Every abstraction leaks somewhere.
Here we look at where.
topics