Title: Karma Attack Description: Automatically respond to device probes with fake networks URL: /latest/wifi/karma/ Version: latest Section: Wi-Fi Search index: /search-index.json # Karma Attack > Automatically respond to device probes with fake networks ## On this page - [Starting Karma](#starting-karma) - [On-device UI](#on-device-ui) - [CLI](#cli) - [Troubleshooting](#troubleshooting) --- Create fake Wi-Fi networks based on SSIDs that nearby devices are searching for. When a device searches for a network, Karma broadcasts it back; when the device connects, a captive portal starts automatically to capture credentials. In automatic mode Karma learns SSIDs from probe requests, while custom mode broadcasts SSIDs you specify. You need a flashed, powered device with a wireless antenna; an SD card is optional for Evil Portal integration. Note: Only test on networks you own or have permission to test. See [Legal and ethical rules](/latest/wifi/basics/#legal-and-ethical-rules). How Karma catches a client ClientAttacker Probe Request (broadcast)The client names an SSID it is looking for Probe Response (spoofed SSID)GhostESP answers as that network association + DHCPThe client joins the fake open network captive portalOptional portal page served on connect Karma answers the networks a device is already asking for. ## Starting Karma ### On-device UI - Open Menu → Wi-Fi → Attacks → Karma Attack. The device will begin learning SSIDs from probe requests. - To use specific SSIDs instead, choose Karma Attack (Custom SSIDs). Enter the SSIDs you want to broadcast (separated by commas), up to 32. - To serve a custom captive portal on the fake networks, choose Karma Attack (Custom Portal). - The device will start broadcasting fake networks. Leave it running to catch devices. - To stop, go back to the menu or select Stop Karma Attack. ### CLI - Run karma start to begin automatic SSID learning. The device will cache SSIDs from probe requests. - Or run karma start SSID1 SSID2 SSID3 to use specific SSIDs (up to 32). Example: karma start FreeWiFi Starbucks McDonald's - Run karma stop when you’re done. The learned-SSID cache holds at most 32 SSIDs. ## Troubleshooting - Fake networks not appearing: Try restarting with karma stop then karma start. - No devices connecting: Ensure devices are actually searching for networks. Try moving closer to the GhostESP device.