Recipe for Defense: Deconstructing an Evil Twin Wi-Fi Attack
An Evil Twin Wi-Fi attack is a hazardous form of wireless rogue access point (AP) spoofing. By broadcasting a Service Set Identifier (SSID) identical to a trusted enterprise or public network, an attacker tricks nearby devices into connecting automatically. Once connected, the attacker occupies a Man-in-the-Middle (MitM) position to inspect unencrypted traffic, inject malicious payloads, or capture credentials.
Understanding the mechanics of an Evil Twin attack from an offensive perspective allows security analysts and network engineers to build resilient 802.11 wireless defenses.
âš¡ Quick Reference: Evil Twin Attack Lifecycle vs. Defensive Controls
Attack Phase Attacker Objective Primary Tool Enterprise Defensive Mitigation 1. Reconnaissance Identify target SSID, BSSID, & Channel airodump-ngWireless Intrusion Detection System (WIDS) 2. Disassociation Force victim off legitimate AP aireplay-ngProtected Management Frames (PMF / 802.11w) 3. Impersonation Broadcast rogue AP with higher signal hostapd,dnsmasq802.1X EAP-TLS Certificate Authentication 4. Interception Capture handshakes or harvest credentials Wireshark,eaphammerNetwork Access Control (NAC) & VPN Enforcement
How an Evil Twin Attack Works (Execution Mechanics)
Wireless devices routinely send out Probe Requests searching for networks they have previously connected to. An Evil Twin attack exploits this trust relationship using a four-step sequence.
Phase 1: Wireless Reconnaissance
The attacker puts their wireless network interface card (NIC) into monitor mode to scan surrounding 802.11 channels for active networks, connected clients, and signal strength (RSSI):
Bash
# Enable monitor mode on wireless interface
sudo airmon-ng start wlan0
# Capture active beacon frames and probe requests
sudo airodump-ng wlan0mon
The output reveals the target network’s BSSID (MAC address), operating Channel, and Encryption Type (WPA2-PSK/WPA3).
Phase 2: Forcing Client Disassociation (Deauth Attack)
To force a victim device to disconnect from its legitimate access point, the attacker transmits spoofed 802.11 management frames (Deauthentication packets):
Bash
# Send 10 deauth frames to a specific client MAC address
sudo aireplay-ng --deauth 10 -a [Target_BSSID] -c [Client_MAC] wlan0mon
Because standard 802.11 management frames are unencrypted by default, the victim device accepts the frame, drops the active connection, and immediately searches for a network with the same SSID to reconnect.
Phase 3: Rogue Access Point Deployment
The attacker launches a rogue AP broadcasting the same SSID on a different channel—often boosted with high transmit power (txpower) to ensure the victim’s device selects the rogue signal over the legitimate one.
A basic hostapd.conf configuration used to spoof an open or WPA2 network looks like this:
Ini, TOML
interface=wlan0mon
driver=nl80211
ssid=Corporate_Guest_WiFi
channel=6
hw_mode=g
auth_algs=1
wpa=2
wpa_key_mgmt=WPA-PSK
wpa_passphrase=TargetPassword123
Phase 4: Traffic Interception & Credential Capture
Once the victim connects to the rogue AP, a local DHCP server (configured via dnsmasq) assigns the victim an IP address and routes their traffic through the attacker’s machine. The attacker can then capture WPA2 4-way handshakes for offline cracking using hashcat or host a captive portal to harvest credentials.
Enterprise Defensive Mitigations
Preventing Evil Twin attacks requires shifting away from basic Pre-Shared Keys (PSK) toward cryptographic identity validation.
1. Mandate 802.1X EAP-TLS Authentication
Ditch standard PSK passwords. Implementing 802.1X with EAP-TLS requires client-side digital certificates. When a user connects, the client device validates the radius server’s certificate. If an attacker deploys a rogue AP without a valid private key signed by the internal Certificate Authority (CA), the victim device automatically rejects the connection.
2. Enforce Protected Management Frames (PMF / 802.11w)
Protected Management Frames encrypt 802.11 management traffic (deauthentication, disassociation, and action frames). This prevents attackers from spoofing deauthentication frames, rendering aireplay-ng deauth attacks ineffective.
3. Deploy Wireless Intrusion Prevention Systems (WIPS)
A dedicated WIPS monitors radio frequency (RF) airspace in real-time. If an unauthorized AP broadcasts an enterprise SSID from an unknown MAC address, WIPS alerts SOC analysts and can automatically transmit localized containment frames to isolate the threat.
Frequently Asked Questions (FAQ)
Can an Evil Twin attack steal my passwords if I visit HTTPS websites?
No, HTTPS encrypts application-layer data between your browser and the website using TLS. However, an attacker on an Evil Twin can see the domains you visit (via plaintext DNS requests or SNI headers) and may attempt SSL stripping attacks (sslstrip) to downgrade HTTP connections if HSTS is not enforced.
How is an Evil Twin attack different from a Rogue Access Point?
A Rogue AP is any unauthorized wireless router plugged into an enterprise network (such as an employee plugging in a home router). An Evil Twin is a specific type of rogue AP designed to explicitly clone the SSID and identity of a legitimate existing network.
#WiFiSecurity #EthicalHacking #InfoSec #Pentesting #CyberTutorial