Login Register






The issue regarding searched threads returning 404s has been fixed. My apologies. - NekoElf
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. filter_list
Author
Message
The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #1
Half of the credit goes to enc0de for his tutorial of mass destruction using mdk3... it helped me a lot to save time.. other wise i had to keep on waiting or deauth clients one by one.

This May be simple and most of you may have done it with better ways.
But my hotspot has client isolation and i am unable to sniff anything using ettercap and other tools. If anyone knows how to do it please share.

My method:
**connect to hotspot and save the login page using "save complete" addon of firefox. it works better than the default save option.

**save the page in localhost.

**Set essid of the ap same as that of hotspot. and connect to the machine. I dont prefer airbase-ng because i have seen that i am never able to connect to fake ap by airbase using linux machine. not sure why.

**start redirecting all request to the ap to the localhost of the machine.
I used <dnsspoof -i wlan0> or dns_spoof plugin of ettercap.

**start mdk3 to disconnect all the clients connected to the real hotspot. Many clients will surely connect to my AP.

I have connected a 10 dbi omnidirectional antenna to my AP. I got it for free...lucky me.

start sniffing tools, i prefer ettercap. No need of MITM, just normal sniffing is enough for me.

Now whoever connects to the AP will be redirected to my localhost with hotspot login page no matter what they request, like the real hostpot.
But the thing is, i dont have internet connection so to make it look less suspicious what i have done is, after they hit login button... they will again be redirected to the same login page with blank username and password field. in this way i gathered a lot of username and passwords..

I have only one problem here.. the dns spoofing is not stable... sometimes it works..sometimes it doesnt..... if anyone has solution to this.. please share.

Also please tell me if there are other better ways.. or anything i can do to make it more accurate.



YEAH YEAH.. GIVE ME NEGATIVE REP FOR SAYING TRUTH... BUT ANYWAY WHO CARES!!!. I AM WHO I AM...REPS DO NOT MATTER TO ME.. GIVE ME 1000 -ve REPS, but IF MY POST IS GOOD THEN READERS WILL KNOW

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #2
Not to sure if you watch hak5 but they have featured a fonera router running custom os. This does the same sort of thing but it allows you to teather it with your laptop so you could maybe teather you laptop to an internet connection via your phone and dishout internet to your connected clients.

http://hakshop.com/products/wifi-pineapple

have a look at the link above.

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #3
it was 5* if you post the commands instead of simple text.

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #4
(06-10-2011, 06:39 PM)Carlcox89 Wrote: it was 5* if you post the commands instead of simple text.

hmm.. i am not clear what you are trying to say....
are you saying it would end in 5 lines if i wrote commands instead of text?
YEAH YEAH.. GIVE ME NEGATIVE REP FOR SAYING TRUTH... BUT ANYWAY WHO CARES!!!. I AM WHO I AM...REPS DO NOT MATTER TO ME.. GIVE ME 1000 -ve REPS, but IF MY POST IS GOOD THEN READERS WILL KNOW

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #5
Deathknight nice fucking share this is the kind of challenges you have to adapt your own little techniques in order to accomplish your goal. This is real life hacking 101 lol.

I really mean it good shit keep it up your getting +rep from me.

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #6
wow.. thank you very much enc0de. I am a big fan of yours. Biggrin
Please Help me in Client Isolation thing if you can. thanks again. Biggrin
YEAH YEAH.. GIVE ME NEGATIVE REP FOR SAYING TRUTH... BUT ANYWAY WHO CARES!!!. I AM WHO I AM...REPS DO NOT MATTER TO ME.. GIVE ME 1000 -ve REPS, but IF MY POST IS GOOD THEN READERS WILL KNOW

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #7
ok explain the situation where you need it done and what your trying to do step by step keep it simple no need to complicate things so I can visualize what your trying to do and see if i can help you or put you in the right direction.

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #8
ok!
I am trying to use sniffing tools directly on the hotspot (real ap).
It seems to be mikrotik with client isolation enabled so that i cant communicate with other clients connected. Because of this i cant sniff the login name and passwords even though it is in plain text. (i have doubt if this is caused by client isolation or not)

my method.
Connect to hotspot.
Start ettercap with/without mitm. Ettercap is properly configured.
I use iptables and sslstrip properly too. It works in other networls.

I can only see pwople getting association with certain ip. And nothing after that.
I cant even ping that ip, this is surely because of CI. But no sniffing at all, i can get any any data.. When i scan for host, i can see only one host, different gateway..main gaeway of hotspot. Even if i connect to other APs of this hotspot company i can see the same gateway even if ip of ap is different. Eg. Ip of hotspot is 1.2.3.4 but the only host shown in ettercap host list is 1.1.1.1. In all aps. Hope u understood and it was not quite cmpleex.
YEAH YEAH.. GIVE ME NEGATIVE REP FOR SAYING TRUTH... BUT ANYWAY WHO CARES!!!. I AM WHO I AM...REPS DO NOT MATTER TO ME.. GIVE ME 1000 -ve REPS, but IF MY POST IS GOOD THEN READERS WILL KNOW

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #9
Have you just tried to sniff the air without connecting to anything i believe you can do that with wifitap. Sniffing the signals in mid air I think is the best way to go but there is a down side if there are alot of PC's and AP's your gonna have a big fucking dump to go through but the upside your learn a thing or two about it. Keep me posted and if you still need more info let me know.

Reply

RE: The Way I Used To Get Hotspot Login Username And Passwords using a wireless router. #10
i havent used wifitap..but i had once sniffed using airodump-ng and used airdecap to decode it...it showed me some links, photos etc....
Ok, i will try doing it..and report you in a couple of days.
YEAH YEAH.. GIVE ME NEGATIVE REP FOR SAYING TRUTH... BUT ANYWAY WHO CARES!!!. I AM WHO I AM...REPS DO NOT MATTER TO ME.. GIVE ME 1000 -ve REPS, but IF MY POST IS GOOD THEN READERS WILL KNOW

Reply







Users browsing this thread: 1 Guest(s)