Skip to main content

Overview

hostapd-mana is a patched version of hostapd that adds rogue AP capabilities. It responds to client probe requests to capture WPA2 handshakes from clients probing for offline networks, and captures MSCHAPv2 credentials from WPA Enterprise clients that connect to a rogue 802.1X server.

Install


Usage


Config: WPA2 PSK Handshake Capture

Captures handshakes from clients probing for a WPA2 network that is not currently in range. hostapd.conf:
Stop with CTRL+C when AP-STA-POSSIBLE-PSK-MISMATCH appears.

Config: WPA Enterprise Credential Capture

Runs a rogue 802.1X/RADIUS server. Captures MSCHAPv2 hashes from connecting clients. Requires FreeRADIUS certificates, see FreeRADIUS section below. network.conf:
EAP user file (/etc/hostapd-mana/mana.eap_user):

Key Config Options


FreeRADIUS Certificate Generation

Required for WPA Enterprise rogue AP: