hostapd-mana
๐ก Wireless ยท C
hostapd-mana is a featureful rogue access point tool based on a modified version of hostapd, the standard Linux access point daemon. Developed by SensePost, it extends hostapd with capabilities specifically useful for wireless penetration testing: it can impersonate any SSID that clients are probing for (karma attack), capture WPA/WPA2 handshakes from connecting clients, downgrade encryption to capture credentials, and integrate with EAP credential harvesting for WPA-Enterprise networks. hostapd-mana acts as a convincing evil twin that automatically responds to client probe requests, tricking devices into connecting and exposing their credentials or traffic. It's commonly used in wireless assessments to test organizational resilience against rogue access point attacks and to capture domain credentials from enterprise wireless clients.
Installation
from source
$ git clone https://github.com/sensepost/hostapd-mana && cd hostapd-mana/hostapd && makeUse Cases
- Deploying evil twin access points to test client association behavior
- Capturing WPA-Enterprise credentials through EAP harvesting
- Performing karma attacks to intercept clients probing for known networks
- Testing organizational defenses against rogue access point attacks
- Conducting wireless MitM assessments with credential downgrade attacks
Tags
Details
- Category
- ๐ก Wireless
- Language
- C
- Repository
- sensepost/hostapd-mana
- Platforms
- ๐งlinux
Links
Alternatives & Comparisons
Aircrack-ng
CComplete suite for WiFi network security assessment. Monitoring, attacking, testing, and cracking.
Compare hostapd-mana vs Aircrack-ngBettercap
GoSwiss army knife for WiFi, Bluetooth, and ethernet network recon and MITM. Scriptable with JS.
Compare hostapd-mana vs BettercapWifite2
PythonAutomated wireless attack tool. Wraps aircrack-ng, reaver, and hashcat for streamlined WiFi auditing.
Compare hostapd-mana vs Wifite2Reaver
CWPS brute force attack tool. Exploits Wi-Fi Protected Setup to recover WPA/WPA2 passphrases from WPS-enabled routers.
Compare hostapd-mana vs ReaverPixiewps
CWPS offline brute force. Exploits weak random number generation in WPS implementations to recover PINs in seconds.
Compare hostapd-mana vs PixiewpsMore in Wireless
Aircrack-ng
CComplete suite for WiFi network security assessment. Monitoring, attacking, testing, and cracking.
Bettercap
GoSwiss army knife for WiFi, Bluetooth, and ethernet network recon and MITM. Scriptable with JS.
Wifite2
PythonAutomated wireless attack tool. Wraps aircrack-ng, reaver, and hashcat for streamlined WiFi auditing.
Kismet
C++Wireless network detector, sniffer, wardriving tool, and IDS. WiFi, Bluetooth, Zigbee, and more.
Flipper Zero Firmware
CCustom firmware for Flipper Zero. Sub-GHz, RFID, NFC, infrared, and GPIO hacking multi-tool.
Fluxion
ShellWPA security auditing tool that uses social engineering for handshake capture via evil twin attacks.