Welcome
'Wi-Fight Club: I am Jack's Evil Twin' will teach you how to deploy rogue AP (Evil Twins) in your client's environment. Using rogue APs lets you test your client's Wireless Intrusion Detection System, passwords, wireless phishing education, and overall wireless security.
We will discuss rogue AP Tactics, Techniques, and Procedures, and how / why they work. In this workshop you will set up a CAPTIVE PORTAL, WPA2, and 802.1x rogue AP. We will also go over OWE and WPA3-SAE transition mode attacks.
We will walk through a scenario at a client's site, then set up a rogue AP to harvest user credentials for the various client networks. We will then crack the harvested credentials. We will finish up with a section on defense. We will be using EAPHAMMER, HOSTAPD-MANA, WIFIPHISHER, and AIRBASE-NG for the rogue AP section. HASHCAT, AIRCRACK-NG, and JOHN for the password cracking section. This workshop is for beginners, but participants should have basic Linux and 802.11 knowledge and be comfortable using virtual machines.
Getting Started
A little prep before class day will let us start on time and get the most out of the workshop:
- Download the workshop VM below and set it up by following the VM Setup Guide. Boot it at least once to confirm it runs and has network connectivity.
- Briefly skim the Lab Guide so you know what to expect and are ready to work through the labs on class day.
- Bring an external Wi-Fi adapter that supports master (AP) mode. This is essential for the workshop. The recommended card is the ALFA AWUS036ACM. See the full requirements in the message to students.
Your laptop should have at least 8 GB RAM, 40 GB of free storage, and an x86_64 Intel/AMD processor. Apple Silicon (M1–M4) is not supported natively and requires an x86 emulation setup. The workshop is beginner-friendly, but basic Linux and 802.11 knowledge will help.
Download the VM
Grab the workshop virtual machine for your hypervisor: