Skip to content

Evil Twin Attacks

Wireless networks are vulnerable to evil twin attacks, where an attacker deploys a rogue access point (AP) that mimics a legitimate one to intercept traffic, steal credentials, or launch further attacks. This section explains how such attacks operate, how to detect them, and strategies to mitigate their impact.


Mechanics of an Evil Twin Attack

An evil twin attack typically follows these steps: 1. Reconnaissance: The attacker identifies a target AP (e.g., a corporate Wi-Fi network) and notes its SSID, BSSID (MAC address), and security protocols. 2. Deployment: The attacker sets up a rogue AP with the same SSID and, if possible, the same BSSID. This AP often uses the same encryption (e.g., WPA2-PSK) to appear legitimate. 3. Luring Victims: The attacker may broadcast the fake AP on the same channel as the target to trick users into connecting. Techniques like deauthentication attacks (e.g., using aireplay-ng) can force users to disconnect from the real AP. 4. Traffic Interception: Once connected, the attacker captures data (e.g., HTTP traffic, credentials) using packet sniffing tools like Wireshark or tcpdump.

Example:

aireplay-ng --deauth 0 -a <target_BSSID> -c <target_client_MAC> <interface>
This command forces a client to disconnect from the legitimate AP, prompting them to reconnect to the evil twin.


Detecting Evil Twin APs

Detection requires proactive monitoring and network analysis: 1. SSID and BSSID Monitoring: Use tools like airodump-ng to track unexpected APs with matching SSIDs or spoofed BSSIDs. 2. DHCP and ARP Anomalies: Monitor for rogue DHCP servers or ARP spoofing using tools like tcpdump:

tcpdump -i <interface> arp
3. Client Behavior Analysis: Look for clients connecting to APs with unusual signal strength or unexpected locations (e.g., a client connecting to an AP in a different geographic region). 4. Network Segmentation: Isolate guest networks and enforce strict access controls to limit lateral movement.


Prevention Strategies

To mitigate evil twin attacks, adopt the following measures: 1. Dynamic SSID Rotation: Regularly change SSIDs to reduce the likelihood of spoofing. Use unique BSSIDs for each AP. 2. 802.1X Authentication: Enforce EAP methods (e.g., EAP-TLS) to require client certificates, making it harder for attackers to impersonate users. 3. MAC Address Filtering: Block unauthorized devices from connecting, though this can be bypassed with MAC spoofing. 4. Wireless Intrusion Detection Systems (WIDS): Deploy systems like Cisco Stealthwatch or Aruba ClearPass to automatically detect and alert on rogue APs. 5. User Education: Train users to verify network credentials and avoid connecting to unknown networks.

Example:
Configure a firewall to block traffic to the evil twin's IP address:

iptables -A FORWARD -d <evil_twin_IP> -j DROP


Key takeaways

  • Evil twin attacks rely on mimicking legitimate APs to intercept traffic, requiring vigilant monitoring and network segmentation.
  • Detection involves analyzing SSID/BSSID anomalies, DHCP/ARP traffic, and client behavior.
  • Prevention includes dynamic SSID rotation, 802.1X authentication, WIDS, and user education to reduce attack surface.
  • Tools like airodump-ng and tcpdump are critical for both attack simulation and defense analysis.