← All cheat sheets

GHOST-PHISHER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Ghost Phisher is a wireless and Ethernet security auditing and
attack tool. It provides fake AP creation, session hijacking,
DNS/DHCP poisoning, credential harvesting, and HTTP/HTTPS server
for phishing pages.

LAUNCHING#

ghost-phisher                    # Launch GUI (requires root)
sudo ghost-phisher               # Launch with root privileges

MODULES#

# Ghost Phisher has several integrated modules:

# 1. Fake Access Point
# 2. Fake DNS Server
# 3. Fake DHCP Server
# 4. Fake HTTP/HTTPS Server
# 5. Session Hijacking
# 6. ARP Poisoning
# 7. Credential Harvester

FAKE ACCESS POINT#

# Set up a rogue wireless access point
# Configure:
# - Interface (wlan0, wlan1)
# - ESSID (network name to impersonate)
# - Channel
# - Security (Open/WEP/WPA)
# - Gateway IP for the fake network

FAKE DNS SERVER#

# Redirect DNS queries to attacker-controlled IPs
# Configure:
# - Listening interface
# - Target domain(s) to spoof
# - Redirect IP address
# Useful for redirecting victims to phishing pages

FAKE DHCP SERVER#

# Provide DHCP leases to connected clients
# Configure:
# - IP range to assign
# - Gateway (attacker IP)
# - DNS server (attacker IP for DNS poisoning)
# - Subnet mask

FAKE HTTP SERVER#

# Serve phishing pages to victims
# Configure:
# - Listening port (80/443)
# - Phishing page template
# - SSL certificate (for HTTPS)
# Captured credentials displayed in GUI

SESSION HIJACKING#

# Capture and replay session cookies
# Configure:
# - Monitoring interface
# - Target protocol/service
# Captured sessions shown in real-time

ARP POISONING#

# Perform ARP spoofing attacks
# Configure:
# - Interface
# - Target IP(s)
# - Gateway IP
# Redirects traffic through attacker machine

CREDENTIAL HARVESTER#

# Built-in templates for common services:
# - Facebook, Twitter, Google login pages
# - Custom HTML templates supported
# Logs captured credentials with timestamps

REQUIREMENTS#

# Dependencies:
# - Python 2.7
# - Scapy
# - aircrack-ng suite
# - dhcpd
# - hostapd
# - dnsmasq
# - Wireless adapter with monitor/injection support

EXAMPLES#

# Basic phishing attack workflow:
# 1. Start fake AP (clone target ESSID)
# 2. Start fake DHCP (assign IPs to victims)
# 3. Start fake DNS (redirect all traffic)
# 4. Start fake HTTP (serve phishing page)
# 5. Monitor credential harvester for captures

NOTES#

- GUI-based tool (Python/Qt)
- Requires wireless adapter supporting AP mode
- Only for authorized penetration testing
- Integrates multiple attack vectors in one tool
- Supports both wireless and wired network attacks
- Log files saved for later analysis
- Some features may require additional tools (airmon-ng)