How Hackers Can Grab Your Passwords Over Wi-Fi with Evil Twin Attacks
HTML-код
- Опубликовано: 21 авг 2024
- Airgeddon Used for an Evil Twin AP with Captive Portal
Full Video: nulb.app/x4a3p
Subscribe to Null Byte: goo.gl/J6wEnH
Kody's Twitter: / kodykinzie
Cyber Weapons Lab, Episode 010 (Recut - Partial Episode)
Wi-Fi networks can be set up by smart IT people, but that doesn't mean the users of the network are similarly tech-savvy. We'll demonstrate how bad actors can use am evil twin attack to steal Wi-Fi passwords. Essentially, they kick a user off their trusted network while creating a nearly identical fake one they connect to. This forces the victim to connect to the fake network and supply the Wi-Fi password to regain internet access.
While a more technical user might spot this attack, it's surprisingly effective against those not trained to look for suspicious network activity. The reason it's so successful is that most users don't know what a real firmware update looks like, leading to confusion in recognizing that an attack is in progress. By knowing all this, it's easier to spot and avoid your Wi-Fi password from being taken right from under you.
To learn more, check out the article and more in-depth video on our website: nulb.app/x4a3p
Follow Null Byte on:
Twitter: / nullbyte
Flipboard: flip.it/3.Gf_0
Website: null-byte.com
Weekly newsletter: eepurl.com/dE3Ovb
Vimeo: vimeo.com/chan...
In reality he blink at the same time we blink so we can’t see when he close his eyes.
???
It's how the Kody hacks you.
@@NullByteWHT 🤣🤣🤣
this comment makes no sense..if you were to busy watching his eyes and not listening you have no clue :D..there's not alot to see...the way he explains it with his voice hits the nail on the head ...'blinking' has nothing to do with this video explaining this dual wifi exploit..and i thought i was drunk!.. + he has to be careful now as youtube are probably pushing him into a corner attempting to de monetise his content ..which in ALL honesty the public interested in there online security needs to see ...catch 22 really go figure
He blinks like every 10 seconds.
One of the few who share their knowledge generously, thank you very much🇲🇦👏👏👏👏👏👏👏👏👏👏
Thanks beauty in! We really do put in a lot of hard work.
شرحي شنو كيقول راه مكنفهموش الانجليزية ؟؟
@@rachidbouali6887 HADA VIDEO TAYAALAM KIFASH GARASSINAT TAYSSARGOU KALIMAT SIR NTAA LWIFI BISTAMAAL 2HOUJOUM FI NAFSS ALWAGT.
I sometimes download these vids so that whenever i go to a place with no internet or a very poor connection, I may get bored.
For sure and you can check out the website too null-byte.wonderhowto.com/
@@NullByteWHT I've got an idea for your next video,
It's an article that i read on the websuite that tells you on "How to not look like a noob while atrending DEF CON" , perhaps you could cover this in a video that would help both hackers and other intrested people who may consider attending the event.
Bah! Are they just trying to demonetize you, or are they removing content? I'm not trying to hack anybody. I'm just trying to understand enough to not become a victim...lol! Anyway, great video. Thank you for sharing!
You can always find all of our content on our website null-byte.wonderhowto.com/
This is a video encouraging hacking.
Nice haircut Kody
Thanks 😃♥
the guy doesn't blink
0:59
FBI open up!!!
gottem
OMG OMG OMG the cats are back! Happy happy happy, Joy joy joy! :-)
😺😺😺
@@NullByteWHT 🥰
lol omg people are more worried about your blinking than youtubes ban, thanks for the video
Very good tutorial. Well explained. 👍
"when you create a fake wireless network, especially one that's based" - Null Byte
Great quality video. I think it is ok to skip the demo time for the attacker side but not for the victim side. That way, viewers can understand how tricky it is. And viewers who want more just have to try it 😏
Thanks for the input, we'll think about it.
But whoever is that dumb to type in their password into a captive portal prompt on their home/work router which obviously is not supposed to be there, deserves to the hacked. lmfao!!
The world's best teacher
Hi Null Byte :) Fellow Software/Bug bounty guy here, hope you are well.
Hey man, cool channel I like the long form python tutorials on the email bomb and keylogger.
@@NullByteWHT Thanks :) I uploaded an hour-long python ransomware tutorial the other day lol, but since reading some comments here I may cut-down on the "hacking" tutorials for a bit seems RUclips is not a safe place for us atm. I enjoy your channel, great stuff, thanks for the content. Have good day :)
Yeah they took down a few of our videos but we keep everything up on our website. null-byte.wonderhowto.com
this guy used to be extremely fucking creepy back when he first shot these videos. Now he is just a sweet guy who just happens not to know how to blink
How to become a cybersecurity professional: make your self a tattoo that in 4:00
It's even a cipher.
How to access internet when government stops the internet or shut downs .
It depends on how they do it, if it's a DNS level block using a DNS like 1.1.1.1 can fix it.
if your running windows pull up command prompt run 'netstat' or ipconfig /all ...look what your dns is doing check it matches up with your router settings and that isn't changed also...click 'start' bring up command prompt very simple ...from your comment i highly doubt the government is shutting down your connection..could be a dodgy line...alot of attenuation...who knows? if in doubt run a vpn ( i always do to protect myself) hard to say with the information you have provided , alot of DNS hijacking going on lately here in my country ...highly doubt your on the governments 'watch' list as you havent explained anything or nothing to go on...look into a dual boot os and run Linux best thing i ever done many years ago ...
90% positive the government won't shut down your connection...it's how they monitor what you do what you search etc etc your personal movements and search history is money ($) to them it's all sold ...it could be anything from malware, a browser hijacker attempting to MIM , or someone simply 'hogging' the bandwith ...to many variables
also run who is...check your public ip address, check the dns matches up with your router , check your router logs, sometimes they will give off red flags to dns hijacking..but from what you've said i've got a funny feeling you'r on a copper line (RIM) and your older brother is watching naughty videos! ;)
HE BLINKED
i serch my youtube history just to watch this again 👍
why evil twin is not automatically connect the victim to fake ap? Please Reply Sir.thank you
I used to use Linset for Evil Twins
Nice, how well did that work?
Why don't he blink ?? I think this guy is a machine 😳
Isn't it possible to figure out the wrong password attempt (target would've entered the password to his network) ? Rather than pursuing the target to enter the password into a phishing page.
I too have the same doubt ! I researched about how to get log wrong attempts by the users but it is not possible I think so. If it possible then it is so easy to setup AP with same name and get the wrong attempts. before that we can do deauth the actual AP.
Bro this man's face cmoes up every wifiphisher video I click
Best content on RUclips, without question
Can you make a collaboration with another RUclipsr named LiveOverflow?
Would be very interesting! :D
We'll look into it 😉
AYYY
COLLAB COLLAB COLLAB
Which is the best wifi adapter for network or wireless network hacking? For Kali Linux
Check out our adapter guide nulb.app/x45q
A comment for your engagement =P
Null Byte engaged
I'm glad you're doing this, because I shelled out $50 to build a wifi pumpkin-pi last month only to find that the software was broken! I can finally put all those tools to use.
The great thing about the Pi is that there are so many uses for it.
Is there a tool that can run a MITM like this, but without the fake portal, instead, when the victim attempts to connect to the evil AP, it will capture the connection packet with the password, and try it against the real AP?
How to configure the phishing page on this airgeddon?
This is for advanced not for beginners... at least you should have shown how to install the Evil Twin!
Does it require 2 wifi adapters ?
Bruh! Why would you type sudo when you're root?!! Nice vid btw
exactly mate!
Mistakes were made....
@@NullByteWHT hey can i ask you a question?
@@rythm3756 yes ask ?
@@shekhar81 i forgot my question xD 1 month ago asdasdasd
And just like that, in blink of an eye, my network was hijacked.
Minus the blink, the Kody isn't programmed to blink.
One way to prevent this type of attack, is to name your SSID the same as your password. #TechnicallyTrue
Sinopulence yeah but usually wifi passwords are complex passwords and not simple ones
You can't be hacked if it's an open network
@@NullByteWHT exactly! Haha
Null Byte well cant people still log passwords through network traffic, or redirect your webpage requests?
@@OhMyJawsh yeh, the point is, you can't have the password hacked if it's public info. MITM just becomes easier. It's not a suggestion, just a joke. Please don't put your password in the SSID. Unless you want to be breached.
legend says that null byte still replies to comments
Airgeddon keeps disconnecting AP from AP when initializing evil portal, and no deauth is done like that. How do I repair that?
How to save/autosave only the *WiFi password*(not login page details) the victim puts in the clone network? (To only know the WiFi password)
Norton blocked access to your website claiming malicious content?
Our website? null-byte.wonderhowto.com
Nullbyte has malicious code on that website. Visit at your own risk.
Hacking the hackers 😮
Do you need a 2 wifi adapter or onky 1?
Thanks for a great vid. Sorry RUclips is a peice nowadays. Keep up the great work.
Marvin Waxler thanks for watching! Tell all of your friends about us! 😃
My hacker landlord (has been trying to evict me) duplicated my exact wifi name without the security of course. How can I gather evidence that it's him. And how do I get him to stop
Does we need 2 wifi adaptor s
You look a little different, darker hair colour? Something I can’t put my finger on, but you’re looking confident and happy🎩😇
Thanks!
Thanks again great video.
Thanks! We really do put in a lot of hard work.
Man , You Are A living legend
and you are a living cringe
So what if someone puts a link to the disclaimer (or even the "accept terms" checkbox) on the fishing page which really describes everything what is going on. Noone ever reads it, but would it enable then to perform such attack perfectly legally? I.e. user grants permission to perform an attack by checking the "accept terms" checkbox(just like we grant permission to use all our private data to google, ms, apple, etc by accepting their terms..
Good thought but it likely wouldn't hold up in court, it's basically just a scam then.
I love your lessons
Youcef Ch thanks for watching! Tell all of your friends about us! 😃
Do you need two wireless cards?
Can you do it without tools.. As it can be done with Dhcpd, airbase-NG and iptables for rerouting
Most likely, tools just make it easy.
Don’t show fake wifi icon help me
Good job sir ........................
Dj Tahir thanks for watching! Tell all of your friends about us! 😃
Intro changed and you blinked. This Day is weird.
The Kody isn't programmed to blink, it must be a glitch.
@@NullByteWHT Think so too. Maybe the shutter speed of the camera is just weird lol
Should we need 2 wifi adaptor for phis attack
I'm surprised that the website was in HTTP and not in HTTPS
Sir in useland mitm in websploit doesn't work sir please make a video on it plzzzzzzzzz sir
Can you put social media phishing pages ?
Can it work with TP link 300mbps USB Wi-Fi adapter ?
But what is the purpose of technique
need 2 wifi card??
i tried eta
it works perfectly but
IN THE FINAL STEP,
the creation of a new WiFi failed need help????
Anymore details
@@NullByteWHT
i did the attack on my internet so all the devices can't connect to the wifi but the fake WiFi isn't showing up
@@NullByteWHT i sent u a screenshot check ur dm's on twitter my name s @Shelby_SZN
plz make a tutorial to dual boot windows and kali.
Good idea roman, I've added it to the list of video ideas.
You should do a video of how not to blink :) !!!!
I was thinking of something like that for the April 1st video
Null Byte THAT WOULD BE AWESOME THX FOR YOUR SUPPORT BRO THIS SHIT IS AWESOME
What's the end goal
I tried using this attack using argeddon but the fake access point is not generating and i suppose there ia a problem in AP window or DHCP window, rest all the functions are performing properly i had installed all the required tools and i am also able to capture the handshake. Please i am stuck and i know i am step away from achieving it.....
I have a question??? Once they put their password into the fake router page. Does it reconnect them back on the internet. So they are relieved and don’t call say “their provider”. You know what I’m saying???
Which laptop should I prefer for good performance and security ..?
Kody uses a MacBook Pro as his daily driver.
I don't understand why it needs to be a captive portal they put password into, and not just the normal password prompt, but i guess there is a good reason
Technically it's possible to set the fake AP's password to say 12345678, but the device on the user's side will not prompt to enter the correct password, it would just display unable to connect. The captive postal password screen looks more legit as many people have used it at airports and other places. But whoever is that dumb to type in their password into a captive portal prompt on their home/work router which obviously is not supposed to be there, deserves to the hacked. lmfao!!
Kody was great on these videos. The new owners are idiots for not continuing to pay Kody.
Shokran Bro🤗
Can you share the adaper that you used?
Is wireless network adaptor is included??
I did all steps but i didn't receive the fake login page what should I do?
Why would the victim go for open network when he know that his network is secured?
Yeah, this evil twin attack doesn't work very well, cuz if the AP of the person is deauthenticating, then the person would reset it, again and again, thinking that is a problem. Other reason is that, the person could be using internet, but not navegating through a browser or entering sites, the person could be like, texting messages, using whatsapp. They would not think entering other wifi connection, and other risk about this attack is that they could see that the signal of the acess point are heavy when aproaching your house, and they could suspect that you are attacking...
Thank you
fluxion?
Yes nulb.app/x43re
Can I use my laptop adapter as fake ap and dongal as scanner
Hey kody u are my hero man. i like u more..
What can i do if only 2 pop up on my screen ap and dhcp, what about the others deauth,control,dns?
Hackers “http networks are insecure” also hackers “got to this http link” 😬 lol and we have to go check your awesome videos 🙃
Yes haha, and checkout our website null-byte.wonderhowto.com
Question I can test this I havent done this myself yet but what's the odds of passing the hash aka input the hash In place of the the password
Just watched the whole video on website, are two wifi adapters needed?
Yes probably. One to de authorize an user by sending an DAuth signal and one is a new fake AP
Yes 2 wifi connections
@@NullByteWHT Awesome thank you!
@@ashish00007 Makes sense, thank you!
no
Bro your website is not working
Need Help - Evil Twin Attack
Issue : Evil twin attack failed to create fake acces point
When doing hands-on on wifi hack using evil twin method, im not able to see any fake acces point has been created.Looks have some issue in AP window like below.
hostapd_free_hapd_data : Interface Wlan 0 wasn't started
How to solve this? Please help...
thanks for sharing, sir
Nulle byte is loosing Kody
Can you add English subtitle to the video in null byte website please..
I’m using kali Linux and ran sudo setup.py etc but it telling me to use python 🐍 3 so now I’m lost
I am relatively new to all of this so bare with me. Is it not possible to create a locked network exactly like the target network and when they try to connect and input the actual password in their settings not a web to make everything more believable (this obviously wont work since our new locked network has a random ass password ) cant we just capture the error key they sent to our network and test it on our machine against the targets previously saved wpa2 handshake.
this videos really help me I'm starting to get into cyber security and videos have helped a lot
as I am saying you are the best
muhammad Azad thank you for watching! Tell all of your friends about us! 😃
Of course I do.😍
What's the name of his intro song?
I don't remember of the top of my head, I can ask the editor later.
@@NullByteWHT Who made it?
Hey Kody, would you be able to do a video on SSL stripping?
Good idea Jakob Wilson, I've added it to the list of video ideas.
do you need 2 wireless net. adp.?
if yes can i do it with 1
one more thing does it work against phones?
thanks
You need two, one to connect to your internet and one to attack the target. And yes they are just small computers.
@@NullByteWHT thanks
You can also do this attack with your laptop's internal wifi card bro, without buying a new external wireless adapter ( but that is only if your laptop's internal wifi card supports monitor mode and packet injection).
@@DrawingWithNoobArtist it does but dont i need 2 adapters anyway?
nope, you dont require 2 adapters.This attack can be performed with your laptop's internal wifi card only.(But only if your laptop's internal wifi card supports monitor mode and packet injection.)
Sir,
Got Error ( on this screen, its supposed an additional wifi interface is chosen, but you don't have anyone at this moment) help..
Same problem is coming you got any solution?????
Se mira que explica muy bien lo malo es que yo no entiendo nd sería mejor q pusiera letras de lo que dice en español
Lo sentimos, vamos a trabajar para obtener voz en español
Please do a video website or Web server hacking.
Most of your videos are mostly wireless hacks, need something different. Thanks
Good idea Pedro Da Silva, I've added it to the list of video ideas.
Sir I have tried so many ways but the router didn't provide me handshake files and also in the monitor mode station and all other columns didn't show any data after sending deauth packets through aireplay-ng.
Router name - Airtel zerotouch 5g broadband
Sir help plzzz
Please help 🙏🙏🙏🙏🙏😭😭😭
How to install an app with a link....?