Pharming Credentials with Evil Portal on Flipper Zero! The Latest Diabolical App for Flipper Zero!
ฝัง
- เผยแพร่เมื่อ 21 พ.ย. 2024
- This week we're exploring the brand new Evil Portal for Flipper Zero!! With the Evil Portal we can create a fake WiFi Hotspot and when someone logs into it, they're directed to a Google login page. If they enter their login credentials, they're stores on the Flipper's SD card!! It's so cool!
NOTE!! I do make my videos a week in advance, currently this app is available on RogueMaster CFW! RogueMaster added the FAP to his firmware after I gave him a preview of this video last week and he knew I validated the app!
BigBroDude6119's GitHub : github.com/big...
-----------------------------------
Amazon List of All the Parts I Use: a.co/0ujD8M9
UberGuidoZ Repo: github.com/Ube...
Uber's DownGit: uberguidoz.git....
I Am Jakoby's Channel: / iamjakoby
-----------------------------------
Check Out The Official Squachtopia Hangout Discord Server!:
/ discord
-----------------------------------
Try SquachWare Community Firmware! :
github.com/ski...
-----------------------------------
Support the Channel at my Patreon!!
www.patreon.co...
-----------------------------------
Follow me on Social Media!
TikTok : / talkingsasquach
Instagram : / talking_sasquach
-----------------------------------
Help Support my Content At Amazon!: www.amazon.com...
-----------------------------------
Thank You SO MUCH For I am Jakoby for the intro, definitely hit up his channel and be sure to subscribe!!!
/ iamjakoby
-----------------------------------
You can see the username and password live on the main screen once it has started you just need to scroll down.
I learned this after I filmed, this is a GREAT point! Thank you!
@@TalkingSasquach im gonna assume you didnt use your primary email and password for the intro…
@@spymorp6024 lol come on, gimme some credit. Slow video down to .25 speed and you can see what i typed
How far you gotta be though?🤔
@@TalkingSasquachsup mate can u make a video on how to make custom portals ?
dude i was on another tut bc it was shorter, and i made the mistake of not holding boot and i looked everywhere and finally resorted to your tut. lesson learned
dont you just love that i forever now watch atleast 3-4 diff peoples vids to make sure of that sasquach i can actually understand him
I would love to see the Flipper and Pwnagotchi work as one big kit.
I think there's a future there somehow!
I'm working with a few people to try and create the pwnagotchi as an app on the flipper. If anyone could help that be cow tits.
@@Simply-AI-Solutions I'd like to help. I believe in this I don't have a pawn to reverse eng the code though. Git hub will have the source or no?
Idk if he recently updated it, but the creator of the Evil Portal made a different tutorial on how to do it without the Arduino thing. I followed it and it works wonderfully. Nice video, thanks
Can you share the link please? Thanks
@@KunwarKochar Yeah. I'm at dinner right now but will send you it by tonight.
@@KunwarKochar I forgot. I'll send it tonight.
@@KunwarKochar Last reply: I just watched his new tutorial as well and it helped a bunch. Highly recommend.
@@drone815 when will you share the link? :)
To erase the fw for an esp32 s3 just change the esp32s2 to esp32s3 and it will work.
Ex:(old) python -m esptool --chip esp32s2 erase_flash
(new)python -m esptool --chip esp32s3 erase_flash
I cannot believe. Soon as I saw the interview I was looking for this. Weeks later it comes up from you and is actually today 🎉🎉🎉
The only problem with the firmware is it would make the tool easp32 wifi marauder unfunctional. So you either go with the evil portal or you go with the esp32 wifi maruder
This is what I was thinking, and why I lost motivation to continue with this process unfortunately.
You have the evil Portal in marauder
@@gandalss1384yeah, now we have evil portal inside Marauder and makes It easier than before not swtching between firmwares but as all in one...
Nice!! I did the web install for the 0.0.2 he just released, 2min tops, cheers
Saw Pen Ace’s video on this a few days ago. I been waiting to watch this one as well😂
Yup, rehash old skiddy tutorials from years ago.
I noticed this in the recent Rogue Master Firmware update. However, the thought of constantly re-flashing the firmware on my WiFi dev board to alternate between this and Marauder seems a tad too laborious for my taste.
It's not too bad, RM added it after I gave him a preview of this video!
That is why you get two.
@@hawaiisidecar I ain't got money for that bro i'm broke af 💀
@@neox0087 ESP32 is cheap.
Yeah, I have the same thought. Was almost considering just getting a 2nd wifi board.
This was so AWESOME!!!
I really enjoying watching all the things this AMAZING tool is capable.
Each time i learn something new to try that you inform us all with is so greatly appreciated!! (At least by me).
Thank you!! I have a HUGE Evil Portal and Marauder update coming up next week!
@@TalkingSasquach ahh yeaahhHH!!
I love you videos man, can you make a part 2 where tou can show us how to create custom index.html + how to link the code to that index? That would be insane! ❤❤
I'm planning an update
im amazed on the amount of people that don't know how to do the evil portal the right way it shouldn't loop it should take them to the Wi-Fi access point
what does 'MD5 hash is not valid' mean?
same issue
And this is exactly why I have to flippers running different firmwares. Xtreme and Unleashed. I’ve noticed they both have apps and protocols that the other doesn’t
I'm spoiled but i have multiple Flippers and wifi boards so I can swap back and forth
@@TalkingSasquach lucky jeeze
Try Momentum, I think It rocks with the best of both firms...
The ultimate prank: if you live with your family or a roomate or if you have someone over, deauth the internet and run the portal so they have no other choice but to use the "free wifi"
You would need to have two flippers because you can’t open any other apps without stopping deauth
@@Logan_5.0 true
@@DaPlushGuy I love showing people their dark web report having them shut down Wi-Fi and joining my hotspot all so I can show them how uninformed they are. It's scary, so they listen and change habits... theoretically
Im running unleashed firmware (unlshd-055) When I use the app builder to upload the application onto the flipper, its throwing an error saying the "MD5 hash doesn't match"?
Same for me
same
Same
Here is a video where they explain how to fix the "md5 has not valid" issue! Around the 5:40 minute mark: th-cam.com/video/U2_dlCvGXWs/w-d-xo.html
when i install from flipC i get an MD5 error don't really know how to fix that?
Great video. Thank you for the content. I followed along, and got the evil portal to work. My wifi marauder is not working, and I assume I have to go back, and flash the FW for it. Will that overwrite anything that I just did for the evil portal?
Yup! I'll have an update soon showing a SUPER easy to go back and forth
my flipper crashes when i run the portal
and for arduino ide it says "Failed uploading: no upload port provided" Sketch uses 741626 bytes (56%) of program storage space. Maximum is 1310720 bytes.
Global variables use 59480 bytes (18%) of dynamic memory, leaving 268200 bytes for local variables. Maximum is 327680 bytes.
Failed uploading: no upload port provided
Same issue I’m on unleashed and evil portal is already installed on my flipper.. I don’t know if I have to flash my marauder, it’s running on version 11.
I tried to install it with Xtreme but when i get to the install part on flip.c, it says "failed to open serial port". How do I fix this?
same here (12/12/2023)
Is it solved on your site?
will you make a tutorial on how to make the google website look like some kind of other website? love the videos keep making the best content
I could but all you need to do is edit the index.html site, not too challenging!
thats just basic web dev. look up how to make a website and thats your awnser .
I got a md5 hash error when I tried to buid it.
Same
3:45. When i click install, it says md5 hash not valid.. just updated my firmware to most recent.. not really sure whats going on
thank you great video easy to follow
i always know its easy and this is a great example
Could you do an updated video on this? If there is an easier way?
You can flash and swtch between firmwares now, more easy than before...just chosing evil portal or Marauder...more than this, you've got Evil Portal inside Marauder to make It easier...
Now.. I DO have the unleashed firmware. I did flash my wifi dev board.. Whenever I hit install (I put it on unleashed,) it says md5 hash not valid. Any work arounds?
im having the same problem did you fuigure it outif so how did you fix it
Where did you get your animated desktop screen? It's impressive.
Hi, the Evil Portal would a way better tool if it could send out BLE Beacons to advertised the AP. Can't seem to find how this works on here it may be a great project or video to make. What are your thoughts?
Damn, I can't remember what my password is for this free wifi that I've never used. 🤔🤣
Works only from PC! From the phone if I access the fake wifi it doesn't send me to any site.
Same
Cool video, loving your channel...
I couldn't get this to work on mobile, it doesn't redirect you to the fake login page, it does on my pc
Does anyone know why this doesn’t work on mobile phones anymore? It’s very successful on laptops, but on mobile phones it simply doesn’t load the .html file. Were phones given a security patch to prevent this?
I have an awok esp32 v3 and an awok esp32 v4 "big chungus". Do you think evil portal would work better on one than another? I want to have one for evil portal and the other for marauder. What do you think would the process still be the same?
Seems to me that it’d be better to have a couple didn’t WiFi dev boards. So I don’t have to continuously remove marauder for portal stuff.
md5 hash is not valid.. help (Xtreme Firmware) am updated
where did you get that lab 401 mousepad?
Tks a lot man... you´re a good man!
And the other thing, do I have to delete what I have on my ESP32 board and flash it with only the files that you talk about in the video and through Arduino?
Will you do an updated video of the Evil Portal? A lot has changed since this video was dropped.
After I build, I click install and I have an Error. MD5 hash is not valid.
Assist my mind here please
I loved the video, but I don't have the original flipper zero board, I have the esp32, will it work for me?
did you 3d print yourself the protective case for the wifi card? if yes, can you share the file ?
AWOK did that one for me and unfortunately I don't have the file
It's on the flipper zero repository from coco I belive
This is why you should use 2FA on all your accounts. One more line of defense. And don't say you would never fall for a scam like the fake Google-login. Say it's 2am, you're waiting for a delayed flight, for some reason your mobile data doesn't work in that corner of the airport, you need to send those files...
So I’m assuming that if I remove the marauder firmware I won’t be able to do anything with marauder on the flipper zero. Should I have two separate boards to be able to do both?
OK, So i know im so close to getting this to work. The access point launches but no pop up is served to the user.
I'm assuming a few things given the fact that im not able to select the same arduino board in my menu as in this video. 2.0.9 doesnt exist in my menu options so i got with the most recent (that they suggest i update to anyway). How and why is the popup not presenting itself?
Does this only work on the official Wifi Devboard? I have a mini one that I got off Tindie
Am getting (Required to lock TCPIP core functionality!) in logs
Think it will work on the Xtreme firmware? I might try it out later. Great video!
It does! I did it today :)
@@felixtrismegistus7489 nice, thx! I still haven't had a chance to do anything yet, maybe later
why can’t i use marauder when I have the evil portal firmware on the wifi board?
i have a error (found unsatisfied imports) how to fix?
Noob question, would marauder deauth and stuff continue to work with this?
Good question, they will not BUT I've got an update video coming up that'll show how to flash back and forth between Evil Portal and Marauder in about a minute all using the Flipper and a single file with a new app!
Hey Talking Sasquach, can i use this on my ESP-32 WROOM ?
Yes you can
@@stoneyproductions5020 thx, ill try
Heyy Talking Sasquach, thank you for the video, the htm page doesn't pop up on phones only on laptops, i dunno how to fix that
It's very frustrating when I get to the part where I have to install all these pip commands. My computer says that it doesn't recognize any of the commands, and I can't go any further
Is it possible, to have on dev board Marauder and Evil Portal ?
I ask myself the same question
Everything is working perfectly for me except when I open evil portal and receive “API mismatch”. I can go past it and evil portal works. How could I resolve the issue? Thanks!
also when i flash for evil portal, my maurader doesnt work. And when i flash for maurader, my evil portal doesnt work. Is there any way where i can get both on the sam ewifi board?
So wait, there's no way to run this alongside Maurader?
Nope! BUT cococode just came out with an ESP32 flasher AND I figured out how to combine all the bin files together so you can flash back and forth between EP and Marauder in like a minute with like 2 button presses
Thanks for the detailed instructions!
How does flipc give u an install button ????? I legit only get a download
Same
why dosent it work for me? when i select start portal it only brings me to an empty logs folder.
this is only possible with official dev board?
Hey can you show how to run marauder on extreme firm ware I can on unleashed but don’t know how to on extreme
Help. The esp32 board crashed at point 14.35 and will no longer power up. Is there a way to reset. I have tried holding boot whilst connecting usb-c but to no avail.
idk whats wrong but when i press start portal it types lot of letters and at the end is #setap=[name of the wifi] and light on wifi module dont light onlz at start of fliper
help someone please
Since installing this my wifi marauder has stopped working. What do I need to do to scan ap again
Amazing, it works great, but only if you connect from the computer. It doesn't work if I connect to wifi from my smartphone
What phone? It works perfectly on my iPhone, I've heard since issues with Safari
@@TalkingSasquachgalaxy note 10 +
Maybe it doesn't work on Android?🤔
Can you set a password on the evil portal from the txt file or by making another file?
so i have a ? mark, in front of where it says evil portal. How do i get rid of if. I thought i got rid of anything that sas qflipper or flipper os ?
Love ur vids man!!
Thanks! I appreciate you!
In 10:01 you say esp32s2 dev module will it still work if i have an esp32d
i followed all the instructions but the webpage where the victim is supposed to enter they credetials doesn't pop up...... Do someone have some advices ?
help mine only says when i try to run it cannot find the text file but it is in the folder with it
Can this all be done on a Mac to flash the dev board ?
can you do this for the awok board?
So i download the pcap file, and put it into Wireshark. But no data shows up in wireshark. What am i doing wrong?
I am a little lost on erasing firmware step. I can't seem to install esptool. Is there a guide for this somewhere?
what happens if i get the "weird api missmatch" as you said? lol
Dude, you are AMAZING!
Keep up all the amazing works brother ❤
Thanks! I appreciate you!
The FAP page doesnt work :/ How do I go around the 3:10min??
im running released. when i first did it, i didnt think it was there, but it was. then i kept doing it, and i must of did something wrong. bcuz it was downloaded on my flipper. now it has a ? mark. I closed qflipper out, even thiught i don't have it on my mac high sierra 10.13. but now i can't get rid of the ? evil portal. Is there a way to delete that. Ive been doing this for hours.
Fli
pc is giving a MD5 hash mismatch when I try to install it...
what can I doo wenn I dont see the bord in power shell ? I doo like you but he give s me massage is not having a direction
Running this on xtreme and everything seems to work fine except the "router manager" with the spoofed log in, doesn't pop up automatically on any of my devices. You have to actually go to the ip address to see the spoof. Can anyone let me know if this norma l or did I do something wrong during installation? I can change the name and html normally, but I just have this small issue.
The Distike can do this and only cost $12. This with a Pi running Kali goes a bit further along with a decent Wifi dongle.
Do you have a link on how I can make that? Will a Pi zero 2 work?
How do i change the html because it’s saying demo for Evelio portal with email and password
FlipC doesn't work anymore any ideas how to compile it yourself?
🔥🔥🔥🔥🔥🔥🔥🔥🔥
You should add a remote control for life machine
ty
You're WElcome!
To change the SSID would you need to recompile evil_portal_app or is there a settings/config file that can be modified?
Would like to bridge this SSID with my phone's hotspot. For example, is it possible (in theory) to create a hotspot / webpage on the Flipper/WifiDevBoard, where if someone passes my logic puzzle it then can bridge over to my android's hotspot for normal internet access?
is this application working on a regular Esp32 too ?
I believe so, but I have not tried yet!
@@TalkingSasquach k i have a esp32 lying around here maybe tomorrow i can give a answer
@@safekilosjoinheroes9727 did u able to run it?
i use unleashed firware so i of course clicked that one. but when i try to instal it there is a error saying: MD5 hash not valid. what do i have to do?
So what do I get thisbuild at?
I get an error saying md5 hash is not available
gonna wait till someone merges this with the maurauder firmware . making them separate is kind of useless . constantly switching firmware isnt a field ready solution . cool proof of concept though
I'm lucky because I've just got multiple dev boards
That is why you have a couple wifi boards.
@@hawaiisidecar still not as usefull as if they both used same firmware . also noone wants to bring lots of gadgets on a pentest. thats why flipoer became famous because it is an all in one thing. otherwise i might aswell do it on the wifi pineapple
@@hawaiisidecar you know it!
@@myname-mz3lo What is loads of gadgets? Just one more extension card. People like you love to put obstacles in their way. I gave you a solution and instead of saying thank you or that's a good idea you come up with a lousy excuse why it won't work.
keep getting md5 hash is not valid error.. any help
sounds like it is a port of the wifiphisher, does the same thing