Evil Twin Access Point | WiFI Pumpkin

October 6, 2016 | Views: 15720

Begin Learning Cyber Security for FREE Now!

FREE REGISTRATIONAlready a Member Login Here

Hello Everyone:

I would like to share how to setup an Evil Twin Access Point.


Operating System: Kali 2.0/WifiSlax 4.11.1/Parrot 3.0.1/2.0.5

In other Linux like UBUNTU you need to install the following dependencies:

  •     Python 2.7
  •     hostapd
  •     isc-dhcp-server
  •     php
  •     aircrack-ng
  •     dnsmasq

WiFi Adapter: TP-LINK TL-WN722N – I use these on my presentation and demo using 2PCSS.

Note: If you are using VMWARE you can bridge the connection, Connect your OS to through WIFI, if you are using PURE Kali use one LAN for internet source and use the WIFI Adapter for FAKE AP



git clone https://github.com/P0cL4bs/WiFi-Pumpkin.git
 cd WiFi-Pumpkin
 ./installer.sh --install

Note: Use sudo or install in root access.


WIFI Pumpkin

WiFi-Pumpkin is a open source security tool that provides the Rogue access point to Man-In-The-Middle and network attacks.


  • Rogue Wi-Fi Access Point
  • Deauth Attack Clients AP
  • Probe Request Monitor
  • DHCP Starvation Attack
  • Credentials Monitor
  • Transparent Proxy
  • Windows Update Attack
  • Phishing Manager
  • Partial Bypass HSTS protocol
  • Support beef hook
  • Mac Changer
  • ARP Poison
  • DNS Spoof
  • Patch Binaries via MITM


Now, I  would like to share the process how to Capture POST Credentials Request using WiFi-Pumpkin.


Step 1: We need to install follow instruction above.

Step 2: Just start using “sudo wifi-pumpkin” after installed


Step 3: Click Start -> View ->Credential NetCreds

Step 4: Capture Logs
Capture Logs

Step 4: If the Victim connected and login to nont-https

Step 5: Viola, you get plain text credentials

This is for educational purpose and thank to the P0cL4bs Team

Stay tuned and I will show you next the tutorial in bypassing HSTS.




Share with Friends
Use Cybytes and
Tip the Author!
Share with Friends
Ready to share your knowledge and expertise?
  1. Error : WiFi-Pumpkin need PyQt4 🙁

Page 4 of 4«1234
Comment on This

You must be logged in to post a comment.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Support Cybrary

Donate Here to Get This Month's Donor Badge


We recommend always using caution when following any link

Are you sure you want to continue?