惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
量子位
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
U
Unit 42
IT之家
IT之家
F
Fortinet All Blogs
GbyAI
GbyAI
MongoDB | Blog
MongoDB | Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Register - Security
The Register - Security
NISL@THU
NISL@THU
Webroot Blog
Webroot Blog
A
Arctic Wolf
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
Recent Announcements
Recent Announcements
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog
P
Palo Alto Networks Blog
Y
Y Combinator Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
有赞技术团队
有赞技术团队
Engineering at Meta
Engineering at Meta
C
Cybersecurity and Infrastructure Security Agency CISA
aimingoo的专栏
aimingoo的专栏
Know Your Adversary
Know Your Adversary
Cyberwarzone
Cyberwarzone
Martin Fowler
Martin Fowler
The Hacker News
The Hacker News
P
Privacy International News Feed
T
Threat Research - Cisco Blogs
G
GRAHAM CLULEY
宝玉的分享
宝玉的分享
博客园 - 聂微东
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
S
Securelist
T
The Exploit Database - CXSecurity.com
T
Threatpost
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
F
Full Disclosure

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP) Bypassing WAFs Using Oversized Requests Getting Started with AI Hacking Part 2: Prompt Injection Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 2) DomCat: A Domain Categorization Tool Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1) Microsoft Store and WinGet: Security Risks for Corporate Environments Default Web Content MailFail Commonly Abused Administrative Utilities: A Hidden Risk to Enterprise Security Stop Spoofing Yourself! Disabling M365 Direct Send Bypassing CSP with JSONP: Introducing JSONPeek and CSP B Gone Offensive Tooling Cheatsheets: An Infosec Survival Guide Resource DNS Triage Cheatsheet GraphRunner Cheatsheet Burp Suite Cheatsheet Impacket Cheatsheet Wireshark Cheatsheet Hashcat Cheatsheet EyeWitness Cheatsheet Nmap Cheatsheet Netcat (nc) Cheatsheet Hunt for Weak Spots in Your Wireless Network with Airodump-ng from the Aircrack-ng Suite Detecting ADCS Privilege Escalation Vulnerability Scanning with Nmap Getting Started with NetExec: Streamlining Network Discovery and Access How to Use Dirsearch Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 3: Arcanum Cyber Security Bot How to Design and Execute Effective Social Engineering Attacks by Phone Abusing S4U2Self for Active Directory Pivoting Why Use a Macro Pad? Espanso: Text Replacement, the Easy Way Caging Copilot: Lessons Learned in LLM Security Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 2: Copilot Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 1: Burpference Intercepting Traffic for Mobile Applications that Bypass the System Proxy How to Root Android Phones Communicating Security to the C-Suite: A Strategic Approach Offline Memory Forensics With Volatility Getting Started with AI Hacking: Part 1 Go-Spoof: A Tool for Cyber Deception How to Test Adversary-in-the-Middle Without Hacking Tools Canary in the Code: Alert()-ing on XSS Exploits How to Hack Wi-Fi with No Wi-Fi Why Your Org Needs a Penetration Test Program Burp Suite Extension: Copy For Light at the End of the Dark Web Avoiding Dirty RAGs: Retrieval-Augmented Generation with Ollama and LangChain Gone Phishing: Installing GoPhish and Creating a Campaign 5 Things We Are Going to Continue to Ignore in 2025 John Strand’s 5 Phase Plan For Starting in Computer Security Questions From a Beginner Threat Hunter GRC for Security Managers: From Checklists to Influence AI Large Language Models and Supervised Fine Tuning Attack Tactics 9: Shadow Creds for PrivEsc w/ Kent & Jordan One Active Directory Account Can Be Your Best Early Warning Introduction to Zeek Log Analysis Indecent Exposure: Your Secrets are Showing Creating Burp Extensions: A Beginner’s Guide Pitting AI Against AI: Using PyRIT to Assess Large Language Models (LLMs) The Top Ten List of Why You Got Hacked This Year (2023/2024) ICS Hard Knocks: Mitigations to Scenarios Found in ICS/OT Backdoors & Breaches Intro to Data Analytics Using SQL Finding Access Control Vulnerabilities with Autorize The Detection Engineering Process Cyber Risk Lessons We Can Learn From Hurricane Preparedness Intro to Desktop Application Testing Methodology What Is Penetration Testing? Adversary in the Middle (AitM): Post-Exploitation Pentesting, Threat Hunting, and SOC: An Overview QEMU, MSYS2, and Emacs: Open-Source Solutions to Run Virtual Machines on Windows
Wi-Fi Forge: Practice Wi-Fi Security Without Hardware
BHIS · 2025-02-27 · via Black Hills Information Security, Inc.

Ben Bowman is a Security Analyst at Black Hills Information Security. He graduated in 2024 with a degree in cyber operations. Ben conducts research as well as tool development outside of testing.

In the world of cybersecurity, it’s important to understand what attack surfaces exist. The best way to understand something is by first doing it. Whether you’re an aspiring penetration tester, a seasoned security researcher, or someone looking to improve your knowledge of wireless networks, the ability to ethically practice Wi-Fi security skills is crucial. But what if you don’t have the necessary hardware or setup to perform these tests? 

This Is Where Wi-Fi Forge Comes In

Wi-Fi Forge is a tool designed by Joe Boyd and me. It was created with the goal of emulating wireless networks, offering a virtual environment where you can practice Wi-Fi security techniques without needing any physical wireless hardware. With Wi-Fi Forge, you can create real-world Wi-Fi networks that your host machine can see. These networks are real to the host machine, which creates an ability for you as a tester to interact with wireless networks as if they were real. This means that the ability to test wireless networks without hardware is no longer beyond grasp. 

Key Features of Wi-Fi Forge 

Wi-Fi Forge as a foundational tool allows for the creation of premade labs to spin up within seconds. Enabling users to immediately begin testing wireless access points and tooling. The tool supports the following protocols: 

  • WPS 
  • WEP 
  • WPA 
  • WPA2 
  • WPA2 Enterprise 
  • WPA3 

But you may be wondering: What if I want to train on a network that isn’t prepackaged with the tool? This is where templating comes in. Wi-Fi Forge was built with templating in mind. Say you have a pentest coming up and you have all the access point names and want to practice attacking these access points with your tools before the engagement. By using the pre-made template and documentation, you can create access points with the same protocols and names (SSID, BSSID, and channel) to practice engaging them before the test begins. You structure the template to your liking, drop it in the tool, and you can spin up a lab identical to the real environment within minutes. 

Who Can Benefit From Wi-Fi Forge? 

This tool helps to serve the security scene at large. With new testers trying to learn about attack surfaces and inherent security risks that exist in the wireless landscape, this tool fills that gap. Wi-Fi Forge supports the security community by helping new testers learn about wireless attack surfaces and risks. It also allows researchers to test tools against wireless access points during development and provides students with practical experience in understanding wireless network vulnerabilities. 

Why is Wi-Fi Forge Novel? 

Wi-Fi Forge is the first tool to actively enable testing wireless networks from a virtualized environment. This tool also sets a precedent for future research. If wireless networks can be completely virtualized for research and testing whose to say that the next generation of research won’t be virtualized. Imagine a tool that could emulate LTE cellular infrastructure to allow researchers to study for vulnerabilities. This is exactly what’s next for the Forge family of tools. Stay tuned. 

Getting Our Hands Dirty

This tool sounds cool! What fun would a demonstration be without hands-on activities? To begin, we need to make sure we have the prerequisites:  

  • Kali, Ubuntu, or Parrot OS Virtual Machine. 
  • 8 GB of RAM 
  • 15GB of storage 
  • A desire to learn about Wi-Fi 

Cool! These requirements are low, and with these requirements met, we can continue. First, we need to install the tool. 

Installation 

To do this you need to navigate to the terminal, for this demonstration I will be using a Kali Linux Virtual Machine. 

Opening a Terminal

Then run the following command to pull the tool down from GitHub and install it. 

git clone https://github.com/blackhillsinfosec/Wifi-Forge && cd Wifi-Forge && sudo ./setup.sh

Installation may take up to an hour, so be patient. This tool is very big. 

Once installation is complete run the command below. 

cd .. && sudo python3 WifiForge.py
Wi-Fi Forge Menu

Then we can use the arrow keys to move up and down to select which lab we want to go through. 

Wi-Fi Forge Lab Selection

For this demonstration, well go through the WPS Pixie Dust Attack, an attack on the WPS security feature (flaw). 

Tmux Interface with WifiForge

The lab should deploy within 10 seconds and be ready for interaction. Here we have two Tmux panes, you can use your mouse to click a pane and focus the pane so that you can interact with it. When attacking WPS to try and gain access to a wireless network the tool for the job is Wifite. 

wifite --wps
Wifite Attacking WPS

Then press CTRL+c at the same time. 

Type 1 and hit enter to select the secure_wifi access point. 

Hacked Wi-Fi 

We have successfully compromised WPS to access a wireless network. 

Conclusion 

BHIS had a problem: What do we do to teach people about the wireless world without making them buy a bunch of hardware? This is our solution.

Special thanks to Will Oldert, Kent Ickler, and Jordan Drysdale for inspiring this and helping make it happen. 


Want to learn more about Wi-Fi Forge? Register now for next week’s webcast taking place Thursday, March 6th, at 1pm EST:

How to Hack Wi-Fi with No Wi-Fi w/ Ben Bowman