awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
FluxionNetwork avatar

FluxionNetwork/fluxion

0
View on GitHub↗
5,776 stars·1,527 forks·HTML·GPL-3.0·13 viewsfluxionnetwork.github.io/fluxion↗

Fluxion

Fluxion is a wireless security auditing framework that tests WPA/WPA2 networks by capturing handshakes and deploying rogue access points with captive portals. It operates by deauthenticating clients from legitimate access points, forcing them to reconnect to a cloned network where a fake authentication page collects the network passphrase.

The tool distinguishes itself through a plugin-based attack lifecycle with mandatory hook functions for consistent execution, multilingual metadata scripts that load attack descriptions based on locale, and a handshake verification pipeline that validates captured credentials through external tools. It supports both passive handshake capture and aggressive deauthentication-based methods, with configurable verification intervals and asynchronous checking modes.

Fluxion provides a complete captive portal phishing framework with DNS redirection, SSL encryption for the portal, internet connectivity emulation, and the ability to inject target network details into portal pages. It includes pre-built router portal interfaces that can be downloaded from a remote repository, along with support for custom portal development. The tool logs attack results and captured credentials, and offers a debug mode for troubleshooting.

Features

  • Wireless Security Frameworks - Provides a modular platform for executing custom wireless attack scripts and managing network traffic interception during penetration testing.
  • Wireless - Launches wireless attacks from the command line with configurable parameters and persistent preferences for repeatable testing.
  • Target Detail Injections - Injects target network ESSID, BSSID, and channel into portal pages before attack launch.
  • DNS Query Interceptors - Intercepts all DNS requests from connected clients and redirects them to a local gateway for captive portal delivery.
  • Captive Portal Redirections - Redirects all DNS queries from connected clients to the local captive portal IP address.
  • Wireless Deauthentication Tools - Sends management frames to disconnect wireless clients, triggering a handshake capture opportunity.
  • Traffic Redirection Tools - Redirects all DNS and HTTP/HTTPS traffic from connected clients to a local captive portal server.
  • Rogue Access Points - Deauthenticates all clients from the legitimate access point, forcing them onto the rogue access point.
  • Wireless Network Scanning - Scans the airwaves to locate and select a specific wireless network as the attack target.
  • WPA Handshake Hash Verifiers - Checks whether a captured handshake file contains a valid WPA/WPA2 hash using a configurable verification tool.
  • Captive Portal Simulations - Adapts router web interfaces to work with the tool's captive portal attack workflow.
  • Variable Injections - Injects target network details into captive portal pages to personalize the phishing attack.
  • Handshake Hash Verifiers - Checks whether a captured handshake is valid using a configurable verifier tool at a set interval.
  • Wireless Security Auditing - Tests WPA/WPA2 wireless networks by capturing handshakes and verifying credentials against dictionary attacks.
  • WPA Password Verifiers - Checks submitted passwords against the target network's WPA/WPA2 key using a server-side script.
  • Lifecycle Hook Definitions - Defines mandatory hook functions for prep, start, stop, and cleanup in attack modules.
  • Wireless Security Auditing - Tests WPA/WPA2 wireless networks by capturing handshakes and launching captive portal attacks for security assessment.
  • Handshake Captures - Captures the 4-way authentication handshake from a target access point by listening or deauthenticating.
  • Handshake Password Verifiers - Checks each submitted password against a captured WPA handshake using cowpatty, pyrit, or aircrack-ng.
  • Handshake Verifications - Validates captured WPA handshakes using external tools with configurable polling intervals.
  • Deauthentication Attacks - Sends deauthentication packets to disconnect devices from the legitimate access point.
  • Attack Hook Definitions - Defines mandatory and optional hook functions for attack lifecycle management.
  • Attack Lifecycle Hooks - Defines mandatory hook functions for preparing, starting, stopping, and cleaning up attacks.
  • Attack Lifecycle Hook Definitions - Defines mandatory and optional lifecycle hooks for attack preparation, execution, and cleanup.
  • Portal Variable Injections - Inserts dynamic values like target SSID, MAC address, and channel into portal pages before an attack begins.
  • Credential Capture Loggers - Logs the verified password and halts the attack, letting clients reconnect to the legitimate access point.
  • Router - Displays a captive portal UI that mimics a specific router manufacturer to increase victim trust.
  • CLI Attack Launchers - Launches attacks directly from the command line with target details and attack type arguments.
  • Custom Portal Interfaces - Allows users to design and integrate their own captive portal HTML pages for tailored phishing campaigns.
  • Branded Portal Interfaces - Builds and integrates branded captive portal interfaces that replicate router login screens for social-engineering attacks.
  • Custom Portal Deployments - Loads user-supplied HTML captive portal pages to tailor the phishing appearance during an attack.
  • Dynamic Captive Portals - Shows a single page that submits passwords via AJAX and displays a success or failure message.
  • Portal Template Downloads - Downloads ready-made captive portal interfaces from a remote repository for wireless phishing attacks.
  • Router Portal Interfaces - Builds and integrates custom captive portal pages that mimic legitimate router login screens.
  • Static Captive Portals - Displays a fixed phishing page that submits passwords to a verifier script and redirects based on correctness.
  • Aggressive - Forces clients to reconnect by sending deauthentication packets, increasing the chance of capturing a handshake.
  • Passive - Monitors network traffic silently without sending deauthentication packets, making the attack undetectable.
  • Credential Session Logs - Records all password attempts and successful credential captures with network details to local log files.
  • Wireless Network Tools - Automated social engineering WPA attack suite.
  • Wireless Security - Social engineering and Wi-Fi auditing tool.
  • Wireless Security Tools - Framework for wireless network auditing and attacks.

Star history

Star history chart for fluxionnetwork/fluxionStar history chart for fluxionnetwork/fluxion

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Fluxion

Similar open-source projects, ranked by how many features they share with Fluxion.
  • v1s1t0r1sh3r3/airgeddonv1s1t0r1sh3r3 avatar

    v1s1t0r1sh3r3/airgeddon

    7,797View on GitHub↗

    airgeddon is a bash-based wireless network audit suite and security toolkit for Linux. It serves as a framework for testing wireless vulnerabilities and verifying network configurations across various encryption standards, including WPA, WEP, and WPS. The project functions as an orchestration layer that integrates a collection of third-party wireless security tools. It features a modular approach to attack vectorization, coordinating tasks such as evil twin simulations with captive portals, WPA handshake interception, and the execution of WPS vulnerability tests. Its capabilities cover a bro

    Shell
    View on GitHub↗7,797
  • wifiphisher/wifiphisherwifiphisher avatar

    wifiphisher/wifiphisher

    14,631View on GitHub↗

    Wifiphisher is a modular security framework designed for wireless penetration testing and social engineering auditing. It functions as a platform for security professionals to assess the resilience of Wi-Fi networks by simulating unauthorized access, performing man-in-the-middle interceptions, and executing credential-harvesting scenarios. The tool distinguishes itself through its ability to combine rogue access point deployment with dynamic phishing interfaces. By forcing wireless clients to associate with deceptive infrastructure, the framework can capture network metadata and inject it int

    Pythonaccess-pointattackmalware
    View on GitHub↗14,631
  • cifertech/esp32-divcifertech avatar

    cifertech/ESP32-DIV

    2,552View on GitHub↗

    ESP32-DIV is a handheld wireless pentesting platform designed for analyzing and disrupting a wide range of wireless protocols. It functions as a multi-band radio analyzer, RFID and NFC tag manipulator, and GPS wardriving logger, providing a unified interface for security auditing and signal research. The project distinguishes itself through a modular radio abstraction that allows switching between Wi-Fi, BLE, Sub-GHz, RFID/NFC, and infrared hardware modules. It features a touch-driven TFT interface for navigating toolsets and managing signal profiles, as well as the ability to emulate Bluetoo

    C++arduinoattackdeauth
    View on GitHub↗2,552
  • chrisk44/hijackerchrisk44 avatar

    chrisk44/Hijacker

    2,512View on GitHub↗

    Hijacker is a Wi-Fi security auditing suite designed for scanning wireless networks, capturing traffic, and recovering credentials. It provides a set of tools for detecting nearby access points and clients, intercepting WPA handshakes, and recovering WPA and WEP passwords. The project features a visual security audit interface that allows for the execution of specialized tools without using a command-line terminal. It includes a dedicated WPS pin recovery tool for extracting access point pins using pixie-dust attacks via external adapters. The toolkit covers network reconnaissance, including

    Javaaircrackairodump-ngandroid
    View on GitHub↗2,512
See all 30 alternatives to Fluxion→

Frequently asked questions

What does fluxionnetwork/fluxion do?

Fluxion is a wireless security auditing framework that tests WPA/WPA2 networks by capturing handshakes and deploying rogue access points with captive portals. It operates by deauthenticating clients from legitimate access points, forcing them to reconnect to a cloned network where a fake authentication page collects the network passphrase.

What are the main features of fluxionnetwork/fluxion?

The main features of fluxionnetwork/fluxion are: Wireless Security Frameworks, Wireless, Target Detail Injections, DNS Query Interceptors, Captive Portal Redirections, Wireless Deauthentication Tools, Traffic Redirection Tools, Rogue Access Points.

What are some open-source alternatives to fluxionnetwork/fluxion?

Open-source alternatives to fluxionnetwork/fluxion include: v1s1t0r1sh3r3/airgeddon — airgeddon is a bash-based wireless network audit suite and security toolkit for Linux. It serves as a framework for… wifiphisher/wifiphisher — Wifiphisher is a modular security framework designed for wireless penetration testing and social engineering auditing.… cifertech/esp32-div — ESP32-DIV is a handheld wireless pentesting platform designed for analyzing and disrupting a wide range of wireless… chrisk44/hijacker — Hijacker is a Wi-Fi security auditing suite designed for scanning wireless networks, capturing traffic, and recovering… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… arismelachroinos/lscript — lscript is a wireless network pentesting framework and keyboard-driven command console. It functions as a security…