Flipper Zero Episode 5: Evil Portals & the Dangers of Free Wi-Fi
文章介绍如何利用Flipper Zero和ESP32 Marauder创建恶意portal,通过模拟合法Wi-Fi网络诱骗用户输入登录信息,从而捕获其凭证进行攻击。 2025-7-24 11:11:0 Author: infosecwriteups.com(查看原文) 阅读量:18 收藏

Fahri

Zoom image will be displayed

In the last episode, we captured and cracked Wi-Fi PMKIDs using Flipper Zero and ESP32 Marauder. It was all about collecting handshakes and decrypting them offline.

This time, we’re flipping the script. What if there was no handshake to crack? What if people just gave you their passwords directly?

You’re sitting at your favorite café or killing time at an airport. You pull out your phone or laptop, and bam! There it is:

  • Free_WiFi_Airport or Café_WiFi_Guest

Zoom image will be displayed

No password. Super convenient. You connect, a splash page appears asking for some login info, maybe an email or a “terms and conditions” checkbox. You click through without thinking twice.

Now imagine that entire setup was fake, and you just gave your credentials to someone sitting two tables away with a Flipper Zero.

Welcome to the world of Evil Portals.

Zoom image will be displayed

An Evil Portal is a fake login page that pops up when someone connects to a rogue Wi-Fi network. It looks legit like what you’d see at an airport or coffee shop. But it’s completely controlled by an attacker.

Once someone enters their credentials, those details get saved and can be used later. Some setups go further and inject malware or harvest session cookies.

  • Plug in your 3-in-1 board and power on your Flipper Zero.

Zoom image will be displayed

Plug in the board
  • Select ESP32 on the board and press the switch to activate it.

Zoom image will be displayed

Activate ESP32 module
  • Go to Go to Apps, then GPIO, then ESP

Zoom image will be displayed

Navigate to Apps on Flipper Zero

Zoom image will be displayed

Open the GPIO section

Zoom image will be displayed

Select the ESP option to launch Evil Portal
  • Choose [ESP32] Evil Portal

Zoom image will be displayed

Choose [ESP32] Evil Portal from the list
  • Select Set AP name and name the AP you want devices to see in their Wi-Fi list.

Zoom image will be displayed

Selecting the AP name option

Zoom image will be displayed

Typing the fake network name
  • Scroll down to Select HTML and select your HTML file

Zoom image will be displayed

Scrolling to Select HTML

Zoom image will be displayed

Choosing your HTML file from the list

Zoom image will be displayed

Github

Zoom image will be displayed

Opening the apps_data folder

Zoom image will be displayed

Navigating into evil_portal

Zoom image will be displayed

Moving files into the html directory
  • Start the Portal. Nearby devices will see a fake open Wi-Fi network. When they connect, they’ll be shown the selected login page. Whatever they type will be logged.

Zoom image will be displayed

Select Start Portal

Zoom image will be displayed

Portal launching with details
Connecting to the fake Wi-Fi network

Zoom image will be displayed

Fake login page displayed and filled

Zoom image will be displayed

Captured credentials shown on Flipper Zero

Evil Portals are a simple but powerful demonstration of how easy it is to exploit trust in public networks. Unlike handshake attacks that require cracking, this method relies entirely on human behavior and most people won’t think twice about entering their credentials on a convincing-looking page.

Don’t forget: this is strictly for educational purposes. Use it only in your own lab, never on unsuspecting users. Stay ethical.

See you in the next episode.

Stay vigilant, stay informed, and stay secure!

Thank You for Reading!

Your interest and attention are greatly appreciated.


文章来源: https://infosecwriteups.com/flipper-zero-episode-5-evil-portals-the-dangers-of-free-wi-fi-f23c340859e4?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh