GithubHelp home page GithubHelp logo

blue-box-project's Introduction

This project is being developed for a proof of concept only!
Use of this in real practice without proper authorization from users or network administrator is against the law.
Play Smart, Learn Smart.

Usage of this concept:
Deauthenicate users from legitimate network and connect them to rogue AP to remove client isolation.
SSLStrip against internal subnet for credential conpromise.
DNSSpoof against internal subnet for proxying responses to useful URLS.
Phishing Links setup on webservers housed on the router to deliver fake content to users.

Future piece of this project:
Add dynamic SSID naming via location-based wifi-probing. I.E. Probe for network with known SSID and clone router to be a rougue AP for that Public Network.
Integrate Nova(https://github.com/DataSoft/Nova) to allow for seamless transition of real users of the real AP to honeypots hosted on the real network, cloned to previous users connected(IP, MAC ADDRESS, Operating System).
Simultaneous mobile to desktop webpages for mobile clients connected to the rogue access point.

To fix:
Allow for either Vlan configuration to setup multiple webservers on different IP addresses internally or setup DNSSpoof to allow for a port-based "fakeip" option instead of strictly the IP address.

Programs Used:

Hwk 0.3.2(http://nullsecurity.net/wireless.html)
-Deauthenticates clients off a given BSSID

SSLStrip 0.9(http://www.thoughtcrime.org/software/sslstrip/)
-Transparent HTTP hijacker and HTTPS redirector

DNSChef 0.1(http://thesprawl.org/projects/dnschef/)
-DNS Proxy for Penetration Testers

To Be Used:

Nova(https://github.com/DataSoft/Nova)
Detects network based reconnaissance efforts and attempts to deny efforts, however in this case, it is used as an attack mechanism

blue-box-project's People

Contributors

sparkyfen avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.