Creating a Wi-Fi honeypot
As an aspiring penetration tester, you may be asked to conduct extensive wireless security testing for your company or a client organization. Creating a rogue access point with an interesting SSID (wireless network name), such as VIP_WiFi
or Company-name_VIP
, will lure employees to establish a connection.
When creating a rogue access point, the objective is to capture user credentials and sensitive information, as well as detecting any vulnerable wireless clients in an organization. The following are some tips to consider when deploying your rogue access point:
- Choose a suitable location to ensure there is maximum coverage for potential victims.
- De-authenticate clients from the real access point, causing them to create an association with the rogue access point.
- Create a captive portal to capture user credentials.
To get started, we are going to use Airgeddon once more as it contains a lot of features and functions that will assist...