Evil Portal

Host a fake Wi-Fi login page to test security awareness

On this page

Create a fake Wi-Fi network that shows a login page when users connect. You need an SD card inserted and mounted; portal files are optional because a default portal is built in. Put custom portal HTML (and any referenced assets) in /mnt/ghostesp/evil_portal/portals/ so listportals can find them.

Note: Only test on networks you own or have permission to test. See Legal and ethical rules.

What a connecting client sees
ClientGhostESP
connects to the portal networkOpen AP run by the device
captive-portal login pageHTTP requests are redirected to the page
submits the formCredentials and keystrokes are saved to the SD card

Starting a portal

On-device UI

  1. Open Menu → Wi-Fi → Evil Portal → Evil Portal. The device will launch the built-in default portal.
  2. To use a custom HTML page, choose Custom Evil Portal instead. Select your page and enter the network name and optional password.
  3. The portal is now running. Clients connecting to the network will see a login page.
  4. To stop, choose Stop Evil Portal or run stopportal in the terminal.

From the Flipper app

  1. On the Flipper app, open Wi-Fi → Evil Portal & Network → Set Evil Portal HTML.
  2. Pick your HTML file (up to 2048 bytes) from the file browser; it is sent and stored for the next start.
  3. Back in Evil Portal, choose Evil Portal to run the command. The UI appends startportal and prompts for arguments.
    • Command format: startportal <path|default> <SSID> [PSK].
    • If using a custom HTML file, replace <path> with the filename. Use default for the built-in portal.
  4. Clients connecting to the network will see your uploaded portal.

CLI

  1. Run listportals to see available portal pages.
  2. Run startportal default MyNetworkName to start with the built-in portal. Or use startportal mypage.html MyNetworkName for a custom page.
  3. (Optional) Add a password: startportal mypage.html MyNetworkName MyPassword.
  4. Push HTML over UART and load it into the portal instead of reading a file:
    • evilportal -c sethtmlstr enables HTML buffer mode; then send [HTML/BEGIN], your HTML, and [HTML/CLOSE] markers over UART.
    • evilportal -c clear clears the buffer and reverts to the default portal.
  5. Run stopportal to shut it down.

Submitted credentials are saved to /mnt/ghostesp/evil_portal/portal_creds_<n>.txt and keystrokes to /mnt/ghostesp/evil_portal/portal_keystrokes_<n>.txt on the SD card.

Testing the portal

  1. Connect to the network from another device.
  2. Open a web browser and navigate to any website. You should see the login page instead.
  3. Submit test credentials. Check the SD card files to confirm they were recorded.

Keep custom portal pages simple and small for faster loading, and use a card reader to transfer files to and from the SD card quickly.

Troubleshooting

  • No portal pages found: Make sure the SD card is mounted and has a /mnt/ghostesp/evil_portal/portals/ folder.
  • Credentials not being saved: Verify the SD card has free space and is properly mounted.
  • Clients don’t see the login page: Try opening a new browser tab or clearing the browser cache on the client device. Also make sure any ‘Private DNS’ or similar setting on the client is turned off.