WiFi Pineapple Nano Basic Manual: Difference between revisions

From Elvis Wiki
(This documentation explain a basic workflow in the web interface of the WiFI Pineapple Nano)
 
No edit summary
 
(3 intermediate revisions by 3 users not shown)
Line 1: Line 1:
== Summary ==  
== Summary ==  


This documentation explain a basic workflow in the web interface of the WiFI Pineapple Nano
This documentation explains a basic workflow in the web interface of the WiFI Pineapple Nano.
== Requirements ==
== Requirements ==


* WiFI Pineapple Nano must have a internet connection (https://wiki.elvis.science/index.php?title=Pineapple_Setup#Internet_connection_Windows)
* Check the basic setup here - especially for internet connection sharing and how to start the web interface: [[Pineapple Setup]]
* Prepare a device that Broadcast an open Wlan SSID
* Prepare an access point which broadcasts a SSID, it works best with an Open WiFi.
* Prepare a device which is connected to the open Wlan
* Prepare a device which is connected to the WiFi - this will be the target.
 
In order to complete these steps, you must have followed [[Some Other Documentation]] before.


== Description ==
== Description ==


=== Step 1 ===
=== Step 1: Recon ===
In the PineAP enable the "PineAP Deamon" and the "Autostart".  
* Enable the "PineAP Deamon" and the "Autostart" in "PineAP".  
====Recon:====
* Start a scan.
* Do a scan
* In the recon scan select the device which is connected to the WiFi and add the MAC address to the filter.
* In the Recon Scan select the device which is connected to the open wlan and add the MAC address to the filter
* Optional: Add all probes to PineAP pool.
* Optional: Add all probes to PineAP Pool
* Select the target SSID and add it to the pool. The SSIDs in the pool will be used for mimicking the legitimate networks, and broadcasting them to make the SSIDs publicly visible.
* Select the target wlan SSID and add it to the pool.
* Save the recon scan.
* save the recoon scan


=== Step 2: Filters ===
* Go to the "Filter" configuration.
* Check if the target MAC is in the filter.
* The configuration of the MAC filter should be in "Allow Mode": Only devices which are in this list are able to connect.
* "SSID Filtering" can be blank.


=== Step 3: PineAP Settings ===
* Check the PineAP settings
* In the PineAP select all boxes except "Capture SSIDs to Pool". (Because we do not want that all SSIDs we found to be broadcasted.) Select "Save PineAP Settings".


=== Step 2 ===
=== Step 4: Deauth Attack ===
====Filters:====
* Go to the Filter Configuration
* Check if the target MAC is in the filter
* The configuration of the MAC filter should be in Allow Mode, so that just devices which are in this list are able to connect.
* SSID Filter should be blank
 
=== Step 3 ===
====PineAP Settings:====
 
In the PineAP select all boxes except "Capture SSIDs to Pool". Because we do not want that all SSIDs we found gonna be broadcasted. After that select "Save PineAP Settings".
 
=== Step 4 ===
Force the target to connect with the Pineapple Nano via deauthentication attack.
Force the target to connect with the Pineapple Nano via deauthentication attack.
* Back to the recon page, select the saved scan or do a new one.
* Select the target device.
* In the Death Multiplier enter 2 and press "Deauth".
* Optional, if the WiFi is encrypted: If you want all clients from the original WiFi to be deauthenticated, select the security method and click on "Capture Handshake". (This only works with WPA and WPA2!) After a few seconds a button with "Deuth attack" will appear. This attack is described here: [[WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack]]. Unfortunately, the target device will not connect to an Open WiFi if it was connected to an encrypted WiFi first.


* Back to the Recoon page, select the saved scan or do a new one
Now, if the original WiFi is an Open WiFi, the client should be kicked and connect to the broadcasted SSID from the Pineapple Nano. Check it in the "Clients" page.
* select the target device
* In the Death Multiplier enter 2 and press "Deauth"
 
now the client should be kicked and connect to the broadcasted SSID from the Pineapple Nano. Check it in the "Clients" page.




== Used Hardware ==
== Used Hardware ==


[[Wifi Pineapple Nano]]
* [[Wifi Pineapple Nano]]




== Further attacks ==
== Further attacks ==
[[Evil Portal with Wifi Pineapple Nano]]
* [[Evil Portal with Wifi Pineapple Nano]]


== Courses ==
== Courses ==


* Ausgewählte Kapitel der IT-Security ILV
* [[Ausgewählte Kapitel der IT-Security]]


== References ==
== References ==

Latest revision as of 11:21, 15 December 2024

Summary

This documentation explains a basic workflow in the web interface of the WiFI Pineapple Nano.

Requirements

  • Check the basic setup here - especially for internet connection sharing and how to start the web interface: Pineapple Setup
  • Prepare an access point which broadcasts a SSID, it works best with an Open WiFi.
  • Prepare a device which is connected to the WiFi - this will be the target.

Description

Step 1: Recon

  • Enable the "PineAP Deamon" and the "Autostart" in "PineAP".
  • Start a scan.
  • In the recon scan select the device which is connected to the WiFi and add the MAC address to the filter.
  • Optional: Add all probes to PineAP pool.
  • Select the target SSID and add it to the pool. The SSIDs in the pool will be used for mimicking the legitimate networks, and broadcasting them to make the SSIDs publicly visible.
  • Save the recon scan.

Step 2: Filters

  • Go to the "Filter" configuration.
  • Check if the target MAC is in the filter.
  • The configuration of the MAC filter should be in "Allow Mode": Only devices which are in this list are able to connect.
  • "SSID Filtering" can be blank.

Step 3: PineAP Settings

  • Check the PineAP settings
  • In the PineAP select all boxes except "Capture SSIDs to Pool". (Because we do not want that all SSIDs we found to be broadcasted.) Select "Save PineAP Settings".

Step 4: Deauth Attack

Force the target to connect with the Pineapple Nano via deauthentication attack.

  • Back to the recon page, select the saved scan or do a new one.
  • Select the target device.
  • In the Death Multiplier enter 2 and press "Deauth".
  • Optional, if the WiFi is encrypted: If you want all clients from the original WiFi to be deauthenticated, select the security method and click on "Capture Handshake". (This only works with WPA and WPA2!) After a few seconds a button with "Deuth attack" will appear. This attack is described here: WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack. Unfortunately, the target device will not connect to an Open WiFi if it was connected to an encrypted WiFi first.

Now, if the original WiFi is an Open WiFi, the client should be kicked and connect to the broadcasted SSID from the Pineapple Nano. Check it in the "Clients" page.


Used Hardware


Further attacks

Courses

References