WiFi Pineapple Nano Basic Manual: Difference between revisions

From Elvis Wiki
m (fixed link)
No edit summary
Line 1: Line 1:
== Summary ==  
== Summary ==  


This documentation explain a basic workflow in the web interface of the WiFI Pineapple Nano
This documentation explains a basic workflow in the web interface of the WiFI Pineapple Nano.
== Requirements ==
== Requirements ==


* WiFI Pineapple Nano must have a internet connection (https://wiki.elvis.science/index.php?title=Pineapple_Setup#Internet_connection_Windows)
* Check the basic setup here - especially for internet connection sharing and how to start the web interface: [[Pineapple Setup]]
* Prepare a device that Broadcast an open Wlan SSID
* Prepare an access point which broadcasts a SSID, it works best with an Open WiFi.
* Prepare a device which is connected to the open Wlan
* Prepare a device which is connected to the WiFi - this will be the target.


== Description ==
== Description ==


=== Step 1 ===
=== Step 1 ===
In the PineAP enable the "PineAP Deamon" and the "Autostart".  
Enable the "PineAP Deamon" and the "Autostart" in "PineAP".  
====Recon:====
====Recon====
* Do a scan
* Start a scan.
* In the Recon Scan select the device which is connected to the open wlan and add the MAC address to the filter
* In the recon scan select the device which is connected to the WiFi and add the MAC address to the filter.
* Optional: Add all probes to PineAP Pool
* Optional: Add all probes to PineAP pool.
* Select the target wlan SSID and add it to the pool.
* Select the target SSID and add it to the pool. The SSIDs in the pool will be used for mimicking the legitimate networks, and broadcasting them to make the SSIDs publicly visible.
* save the recoon scan
* Save the recon scan.
 
 


=== Step 2 ===
=== Step 2 ===
Check the filters
Check the filters.
====Filters:====
====Filters:====
* Go to the Filter Configuration
* Go to the "Filter" configuration.
* Check if the target MAC is in the filter
* Check if the target MAC is in the filter.
* The configuration of the MAC filter should be in Allow Mode, so that just devices which are in this list are able to connect.
* The configuration of the MAC filter should be in "Allow Mode": Only devices which are in this list are able to connect.
* SSID Filter should be blank
* "SSID Filtering" can be blank.


=== Step 3 ===
=== Step 3 ===
Line 33: Line 31:
====PineAP Settings:====
====PineAP Settings:====


In the PineAP select all boxes except "Capture SSIDs to Pool". Because we do not want that all SSIDs we found gonna be broadcasted. After that select "Save PineAP Settings".
In the PineAP select all boxes except "Capture SSIDs to Pool". (Because we do not want that all SSIDs we found to be broadcasted.) Select "Save PineAP Settings".


=== Step 4 ===
=== Step 4 ===
Force the target to connect with the Pineapple Nano via deauthentication attack.
Force the target to connect with the Pineapple Nano via deauthentication attack.


* Back to the Recoon page, select the saved scan or do a new one
* Back to the recon page, select the saved scan or do a new one.
* select the target device
* Select the target device.
* In the Death Multiplier enter 2 and press "Deauth"
* In the Death Multiplier enter 2 and press "Deauth".
* Optional, if the WiFi is encrypted: If you want all clients from the original WiFi to be deauthenticated, select the security method and click on "Capture Handshake". (This only works with WPA and WPA2!) After a few seconds a button with "Deuth attack" will appear. This attack is described here: [[WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack]]. Unfortunately, the target device will not connect to an Open WiFi if it was connected to an encrypted WiFi first.


Now, the client should be kicked and connect to the broadcasted SSID from the Pineapple Nano. Check it in the "Clients" page.
Now, if the original WiFi is an Open WiFi, the client should be kicked and connect to the broadcasted SSID from the Pineapple Nano. Check it in the "Clients" page.





Revision as of 11:17, 15 December 2024

Summary

This documentation explains a basic workflow in the web interface of the WiFI Pineapple Nano.

Requirements

  • Check the basic setup here - especially for internet connection sharing and how to start the web interface: Pineapple Setup
  • Prepare an access point which broadcasts a SSID, it works best with an Open WiFi.
  • Prepare a device which is connected to the WiFi - this will be the target.

Description

Step 1

Enable the "PineAP Deamon" and the "Autostart" in "PineAP".

Recon

  • Start a scan.
  • In the recon scan select the device which is connected to the WiFi and add the MAC address to the filter.
  • Optional: Add all probes to PineAP pool.
  • Select the target SSID and add it to the pool. The SSIDs in the pool will be used for mimicking the legitimate networks, and broadcasting them to make the SSIDs publicly visible.
  • Save the recon scan.

Step 2

Check the filters.

Filters:

  • Go to the "Filter" configuration.
  • Check if the target MAC is in the filter.
  • The configuration of the MAC filter should be in "Allow Mode": Only devices which are in this list are able to connect.
  • "SSID Filtering" can be blank.

Step 3

Check the PineAP settings

PineAP Settings:

In the PineAP select all boxes except "Capture SSIDs to Pool". (Because we do not want that all SSIDs we found to be broadcasted.) Select "Save PineAP Settings".

Step 4

Force the target to connect with the Pineapple Nano via deauthentication attack.

  • Back to the recon page, select the saved scan or do a new one.
  • Select the target device.
  • In the Death Multiplier enter 2 and press "Deauth".
  • Optional, if the WiFi is encrypted: If you want all clients from the original WiFi to be deauthenticated, select the security method and click on "Capture Handshake". (This only works with WPA and WPA2!) After a few seconds a button with "Deuth attack" will appear. This attack is described here: WiFi Pineapple Mark VII: Cracking WPA/WPA2-PSK with a dictionary/brut-force attack. Unfortunately, the target device will not connect to an Open WiFi if it was connected to an encrypted WiFi first.

Now, if the original WiFi is an Open WiFi, the client should be kicked and connect to the broadcasted SSID from the Pineapple Nano. Check it in the "Clients" page.


Used Hardware


Further attacks

Courses

References