Title: Evil Portal Description: Host a fake Wi-Fi login page to test security awareness. URL: /v2.1/wifi/evil-portal/ Version: v2.1 Section: Wi-Fi Search index: /search-index.json # Evil Portal > Host a fake Wi-Fi login page to test security awareness. ## On this page - [Prerequisites](#prerequisites) - [Starting a portal](#starting-a-portal) - [On-device UI](#on-device-ui) - [From the Flipper app](#from-the-flipper-app) - [Command line](#command-line) - [What gets recorded](#what-gets-recorded) - [Testing the portal](#testing-the-portal) - [Tips](#tips) - [Troubleshooting](#troubleshooting) --- Create a fake Wi-Fi network that shows a login page when users connect. Note: Only test this on networks you own or have explicit permission to test. Unauthorized access to networks is illegal in most jurisdictions. ## Prerequisites - SD card inserted and mounted. - Portal files saved to the SD card (optional; there’s a default portal built in). - Custom portal files go in /mnt/ghostesp/evil_portal/portals/ on the SD card. Place your HTML (and any referenced assets) there so listportals can find them. ## Starting a portal ### On-device UI - Open WiFi → Evil Portal → Start Evil Portal. The device will launch the built-in default portal. - To use a custom HTML page, choose Start Custom Evil Portal instead. Select your page and enter the network name and optional password. - The portal is now running. Clients connecting to the network will see a login page. - To stop, go back to the menu or run stopportal in the terminal. ### From the Flipper app - On the Flipper app, open WiFi → Evil Portal & Network → Set Evil Portal HTML. - Pick your HTML file (up to 2048 bytes) from the file browser; it is sent and stored for the next start. - Back in Evil Portal, choose Evil Portal to run the command. The UI appends startportal and prompts for arguments. Command format: startportal <path|default> <SSID> [PSK]. - If using a custom HTML file, replace <path> with the filename. Use default for the built-in portal. - Clients connecting to the network will see your uploaded portal. ### Command line - Run listportals to see available portal pages. - Run startportal default MyNetworkName to start with the built-in portal. Or use startportal mypage.html MyNetworkName for a custom page. - (Optional) Add a password: startportal mypage.html MyNetworkName MyPassword. - Run stopportal or stop to shut it down. ## What gets recorded - Submitted credentials are saved to /mnt/ghostesp/evil_portal/portal_creds_<n>.txt on the SD card. - Keystrokes are logged to /mnt/ghostesp/evil_portal/portal_keystrokes_<n>.txt. ## Testing the portal - Connect to the network from another device. - Open a web browser and navigate to any website. You should see the login page instead. - Submit test credentials. Check the SD card files to confirm they were recorded. ## Tips - Keep custom portal pages simple and small for faster loading. - Use a card reader to transfer files to/from the SD card quickly. ## Troubleshooting - No portal pages found: Make sure the SD card is mounted and has a /mnt/ghostesp/evil_portal/portals/ folder. - Credentials not being saved: Verify the SD card has free space and is properly mounted. - Clients don’t see the login page: Try opening a new browser tab or clearing the browser cache on the client device. Also make sure any ‘Private DNS’ or similar setting on the client is turned off.