Captive Portal Phishing
More Wi-Fi time for your work password is not a deal.
What Is Captive Portal Phishing?
The sign-in page a public network shows to get you online is a captive portal, and a genuine one asks for your agreement and an email at most. A fake one offers you more time in exchange for signing in with a work account, and once you type that password the account is not yours alone. You will get online at a cafe, watch what the trade costs, then change the password, sign out the other sessions, and report it.
What You'll Learn in Captive Portal Phishing
- Recognize that no Wi-Fi sign-in page needs a password, a certificate, or an app install.
- Treat an offer of longer or faster access in exchange for a work sign-in as phishing.
- Read an impossible-travel alert as a sign that credentials were used from somewhere you are not.
- Contain an exposed account in order: get onto a connection you control, change the password, revoke the other sessions, then report it.
Captive Portal Phishing — Training Steps
-
Getting online
Alice takes a table at Wrenloft Coffee with a morning of work ahead of her, a deck to finish before a review at eleven. First she needs Wi-Fi. The cafe's guest network is open and top of the list.
-
Twenty minutes of free
The moment she opens her browser, a sign-in page fills it, the way a cafe's Wi-Fi page usually does. It is branded Netfora Secure Access. She is already online, it says, on twenty minutes of free guest access. To keep the connection past that, she should sign in with a work or school account. Nineteen minutes will not get her to eleven.
-
She takes the offer
The trade looks ordinary, so Alice takes it. She types the Ostmere email and password she is signed in with all day anyway, the page tells her she is on until closing, and nothing about her morning looks off.
-
The password lands
Bob is at the next table. Her laptop went looking for a sign-in page and his answered first, so her traffic runs through his machine and everything typed into that page comes to him. He never had to demand a work password, or withhold anything to get one. She was online before she typed and online after: the twenty-minute cap was his invention, and letting her browse costs him nothing while keeping her from asking at the counter. Now he takes the login she entered and, through a server of his own in another city, signs in to the Ostmere portal as her. The captured password goes to Bob's own host, and the login to Ostmere comes from there, not from the cafe. So the account signs in from a city Alice is nowhere near.
-
Inside her account
He lands on Alice's desk. Her projects, her tasks, her account settings. All of it opened with a password she typed to get online at a cafe.
-
A sign-in she did not make
Alice could not tell anything was wrong from her own screen. What tells her is the security team, who watch for exactly this.
-
What should have stopped her
-
Get off his network
First move, before she touches the account: leave the network the sign-in page came through. Her laptop is still on it, and everything she does crosses the machine that answered her.
-
Turn on your hotspot
Rather than trust another network in the room, Alice uses one that is unambiguously hers. She turns on her phone's personal hotspot, and the phone shows its name and its own password.
-
Join your own network
Her phone now shows up in the laptop's network list, secured with the password the phone is showing. She joins it, and from here everything she does runs over a link she owns.
Security Framework Coverage
CWE
- CWE-451 User Interface (UI) Misrepresentation of Critical Information
MITRE ATT&CK
- T1056.003 Input Capture: Web Portal Capture
CIS Controls
- CIS 12 Network Infrastructure Management
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.IR Technology Infrastructure Resilience