The Infernal-Twin is an automated tool designed for penetration testing activities, it has been developed to automate the Evil Twin Attack.
TheÂ Infernal-Twin is an automated tool designed for penetration testing activities, it has been developed to assess wireless security by automating theÂ Evil Twin Attack.
âThe tool was created to help the auditors and penetration testers to perform wireless security assessment in a quick manner and easing complex attack vectors.â states Khalilov M, the author.
Be aware, as usually happen, penetration testing tool could be misused by hackers to conduct illicit activities, so I decided to present it to spread awareness about this potential weapon in the arsenal of attackers.
Let us start explaining the attack scenario,Â on the âEvil Twinâ attack, the attacker set up a bogus Wi-Fi access point, purporting to provide wireless Internet services, but eavesdropping the userâs traffic.
The bogus Access Point is used to serve to the users in the network faked login pages to steal their Wi-Fi credentials and other sensitive data. The attack scenario could be exploited to runÂ man-in-the-middle attacksÂ or to serve malware to the computers in the targeted network.
First of all you need to install all the components necessary to use the tool, including the Apache module, the mysql database, the Scapy packet manipulation tool for computer networks and the wxtools debugging framework.
Then you have to install the Aircrack-ng utility and get the infernal-twin from the repository.
Aircrack-ng is a network software suite consisting of a detector, packet sniffer, WEP and WPA/WPA2-PSK cracker and analysis tool for 802.11 wireless LANs.
At this point launch the Infernal-Twin tool with super administrator privileges. Some users experienced problems connecting to the Database, the user @lightos provided the following solution to fix the issue.
Create a new user on the database and use it for launching the tool by following thisÂ procedure:
Delete dbconnectÂ .conf file from the Infernal wireless folder
Run the following command from your mysql console.
mysql> use mysql;
mysql> CREATE USER âroot2â@âlocalhostâ IDENTIFIED BY âenter the new password hereâ;
mysql> GRANT ALL PRIVILEGES ON \*.\* TO âroot2â@âlocalhostâ WITH GRANT OPTION;
Try to run the tool again.
The Infernal -Twin tools implements several features, it provides all the necessary to hack a Wireless network (WPA2, WEP) and easily allows to runÂ Wireless Social Engineering attacks. Below the principal features:
GUI Wireless security assessment SUIT
WPA2 Enterprise hacking
Wireless Social Engineering
Note taking function
Data is saved into Database
The author of the Infernal-Twin hacking tool, Khalilov M, aka 3ntr0py (entropy1337), announced that next releases will include parsing t-shark log files for gathering victimâs credentials and other data.
In the following video is it illustratedÂ an attack on public network, the script should be able to go and modify the login page and alter the content of it with necessary variables.
Below another video turorial on the Infernal-Twin Tool.
If you are interested in Wireless hacking for penetration testing give a look also toÂ WiFiPhisher, a WiFi social engineering tool that allows an attacker to steal credentials from users of secure WiFi networks.
WiFiPhisherÂ was developed by the Greek security expert George ChatzisofroniouÂ andÂ is available for download on the software development website GitHub.