Captive Portal Phishing

Captive Portal Phishing

More Wi-Fi time for your work password is not a deal.

What Is Captive Portal Phishing?

The sign-in page a public network shows to get you online is a captive portal, and a genuine one asks for your agreement and an email at most. A fake one offers you more time in exchange for signing in with a work account, and once you type that password the account is not yours alone. You will get online at a cafe, watch what the trade costs, then change the password, sign out the other sessions, and report it.

What You'll Learn in Captive Portal Phishing

Captive Portal Phishing — Training Steps

  1. Getting online

    Alice takes a table at Wrenloft Coffee with a morning of work ahead of her, a deck to finish before a review at eleven. First she needs Wi-Fi. The cafe's guest network is open and top of the list.

  2. Twenty minutes of free

    The moment she opens her browser, a sign-in page fills it, the way a cafe's Wi-Fi page usually does. It is branded Netfora Secure Access. She is already online, it says, on twenty minutes of free guest access. To keep the connection past that, she should sign in with a work or school account. Nineteen minutes will not get her to eleven.

  3. She takes the offer

    The trade looks ordinary, so Alice takes it. She types the Ostmere email and password she is signed in with all day anyway, the page tells her she is on until closing, and nothing about her morning looks off.

  4. The password lands

    Bob is at the next table. Her laptop went looking for a sign-in page and his answered first, so her traffic runs through his machine and everything typed into that page comes to him. He never had to demand a work password, or withhold anything to get one. She was online before she typed and online after: the twenty-minute cap was his invention, and letting her browse costs him nothing while keeping her from asking at the counter. Now he takes the login she entered and, through a server of his own in another city, signs in to the Ostmere portal as her. The captured password goes to Bob's own host, and the login to Ostmere comes from there, not from the cafe. So the account signs in from a city Alice is nowhere near.

  5. Inside her account

    He lands on Alice's desk. Her projects, her tasks, her account settings. All of it opened with a password she typed to get online at a cafe.

  6. A sign-in she did not make

    Alice could not tell anything was wrong from her own screen. What tells her is the security team, who watch for exactly this.

  7. What should have stopped her

  8. Get off his network

    First move, before she touches the account: leave the network the sign-in page came through. Her laptop is still on it, and everything she does crosses the machine that answered her.

  9. Turn on your hotspot

    Rather than trust another network in the room, Alice uses one that is unambiguously hers. She turns on her phone's personal hotspot, and the phone shows its name and its own password.

  10. Join your own network

    Her phone now shows up in the laptop's network list, secured with the password the phone is showing. She joins it, and from here everything she does runs over a link she owns.

Security Framework Coverage

CWE

  • CWE-451 User Interface (UI) Misrepresentation of Critical Information

MITRE ATT&CK

  • T1056.003 Input Capture: Web Portal Capture

CIS Controls

  • CIS 12 Network Infrastructure Management

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.IR Technology Infrastructure Resilience