Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 614 Vote(s) - 3.45 Average
  • 1
  • 2
  • 3
  • 4
  • 5
The Way I Used To Get Hotspot Login Username And Passwords using a wireless router.

#1
Half of the credit goes to enc0de for his tutorial of mass destruction using mdk3... it helped me a lot to save time.. other wise i had to keep on waiting or deauth clients one by one.

This May be simple and most of you may have done it with better ways.
But my hotspot has client isolation and i am unable to sniff anything using ettercap and other tools. If anyone knows how to do it please share.

My method:
**connect to hotspot and save the login page using "save complete" addon of firefox. it works better than the default save option.

**save the page in localhost.

**Set essid of the ap same as that of hotspot. and connect to the machine. I dont prefer airbase-ng because i have seen that i am never able to connect to fake ap by airbase using linux machine. not sure why.

**start redirecting all request to the ap to the localhost of the machine.
I used <dnsspoof -i wlan0> or dns_spoof plugin of ettercap.

**start mdk3 to disconnect all the clients connected to the real hotspot. Many clients will surely connect to my AP.

I have connected a 10 dbi omnidirectional antenna to my AP. I got it for free...lucky me.

start sniffing tools, i prefer ettercap. No need of MITM, just normal sniffing is enough for me.

Now whoever connects to the AP will be redirected to my localhost with hotspot login page no matter what they request, like the real hostpot.
But the thing is, i dont have internet connection so to make it look less suspicious what i have done is, after they hit login button... they will again be redirected to the same login page with blank username and password field. in this way i gathered a lot of username and passwords..

I have only one problem here.. the dns spoofing is not stable... sometimes it works..sometimes it doesnt..... if anyone has solution to this.. please share.

Also please tell me if there are other better ways.. or anything i can do to make it more accurate.



Reply

#2
Not to sure if you watch hak5 but they have featured a fonera router running custom os. This does the same sort of thing but it allows you to teather it with your laptop so you could maybe teather you laptop to an internet connection via your phone and dishout internet to your connected clients.

[To see links please register here]


have a look at the link above.
Reply

#3
it was 5* if you post the commands instead of simple text.
Reply

#4
Quote:(06-10-2011, 06:39 PM)Carlcox89 Wrote:

[To see links please register here]

it was 5* if you post the commands instead of simple text.

hmm.. i am not clear what you are trying to say....
are you saying it would end in 5 lines if i wrote commands instead of text?
Reply

#5
Deathknight nice fucking share this is the kind of challenges you have to adapt your own little techniques in order to accomplish your goal. This is real life hacking 101 lol.

I really mean it good shit keep it up your getting +rep from me.
Reply

#6
wow.. thank you very much enc0de. I am a big fan of yours. :biggrin:
Please Help me in Client Isolation thing if you can. thanks again.
Reply

#7
ok explain the situation where you need it done and what your trying to do step by step keep it simple no need to complicate things so I can visualize what your trying to do and see if i can help you or put you in the right direction.
Reply

#8
ok!
I am trying to use sniffing tools directly on the hotspot (real ap).
It seems to be mikrotik with client isolation enabled so that i cant communicate with other clients connected. Because of this i cant sniff the login name and passwords even though it is in plain text. (i have doubt if this is caused by client isolation or not)

my method.
Connect to hotspot.
Start ettercap with/without mitm. Ettercap is properly configured.
I use iptables and sslstrip properly too. It works in other networls.

I can only see pwople getting association with certain ip. And nothing after that.
I cant even ping that ip, this is surely because of CI. But no sniffing at all, i can get any any data.. When i scan for host, i can see only one host, different gateway..main gaeway of hotspot. Even if i connect to other APs of this hotspot company i can see the same gateway even if ip of ap is different. Eg. Ip of hotspot is 1.2.3.4 but the only host shown in ettercap host list is 1.1.1.1. In all aps. Hope u understood and it was not quite cmpleex.
Reply

#9
Have you just tried to sniff the air without connecting to anything i believe you can do that with wifitap. Sniffing the signals in mid air I think is the best way to go but there is a down side if there are alot of PC's and AP's your gonna have a big fucking dump to go through but the upside your learn a thing or two about it. Keep me posted and if you still need more info let me know.
Reply

#10
i havent used wifitap..but i had once sniffed using airodump-ng and used airdecap to decode it...it showed me some links, photos etc....
Ok, i will try doing it..and report you in a couple of days.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through