How can I use parabolic antenna to strengthen access point signal for evil-twin penetration testing?

I am using TP-LINK TL-WN722N v1.x for evil-twin penetration testing but the signal is not stronger than the target access point, so the attack is easily recognizable. I am trying to figure out how can I the strengthen the signal of the TP-… Continue reading How can I use parabolic antenna to strengthen access point signal for evil-twin penetration testing?

Setting up my own wifi: what information can I gather from connected users [on hold]

Can this information be gathered by only sniffing the traffic of an open wifi network or a wifi you own?

Location of where the users live
Websites they visit 
Personal communications, such as emails, chats and messages whom… Continue reading Setting up my own wifi: what information can I gather from connected users [on hold]

Does getting a challenge and response with hostapd-wpe mean that credentials were sent?

I setup an access point to perform an “evil twin” attack on an existing WPA2 Enterprise network (I have permission to do this).

I am using hostapd-wpe. Within a short period of enabling the access point my devices see the ne… Continue reading Does getting a challenge and response with hostapd-wpe mean that credentials were sent?

How dangerous is 802.1x PEAP with a RADIUS server cert signed by a public CA?

I am concerned about wifi evil twin attacks…

Assume I deploy a RADIUS server for 802.1x PEAP/MSCHAPv2 authentication, and Active Directory credentials are used to authenticate user.
Assume my RADIUS servers are radius01.c… Continue reading How dangerous is 802.1x PEAP with a RADIUS server cert signed by a public CA?