Karma
karma / km β Anti-Client Rogue-AP Suite
Targets clients, not access points. Phones and laptops constantly broadcast probe requests for the networks in their saved list (PNL). Karma harvests those, fingerprints the physical devices behind them, and lets you bait a network a client wants β either a WPA2 half-handshake (crackable offline) or an open captive portal (credential capture).
CMD> km β harvest + live table (interactive)
CMD> km auto β hands-free: harvest, then bait the top SSIDs in a loop
CMD> km hs <ssid> [ch] β WPA2 half-handshake bait for one SSID
CMD> km portal <ssid> β open AP + captive portal for one SSID
Works headless β SD and GPS are enrichment only, never required.
Auto mode β km auto
Fire-and-forget. Karma cycles between two phases until you press [q]:
- Harvest (~30 s) β sniff probe requests, build the SSID/device tables.
- Bait sweep β bait up to 8 SSIDs per sweep for ~20 s each (or until a client sends M2). It picks least-recently-baited first (popularity as tiebreak), so across sweeps it rotates through every harvested network instead of looping the same few, and an SSID that yields a handshake is marked captured and skipped from then on.
Reactive (follow-the-probe). While baiting an SSID, if a device probes for a different un-captured network, the clone instantly retargets to that SSID (when the current target is idle) and tries to capture it while the device is actively searching β instead of waiting for the round-robin to reach it. It even baits SSIDs that were never harvested but get probed live. This is silent (no deauth) and is the mechanism that makes km auto effective; the round-robin is just the fallback when nothing is being probed.
Every client that completes the half-handshake is:
- saved to a crackable
/apps/karma/<ssid>.cap, and - logged to
/apps/karma/connects.csv(time, ssid, sta_mac, vendor, type).
The auto screen shows the live AP table (same SSID / DEV / HIT / RSSI columns as the interactive harvest): it auto-scrolls the pages hands-free, marks captured networks green with a trailing *, and highlights the current bait target. A status line shows the phase, countdown, and (during a bait) the Asc/M1/M2 stage counters.
Press [v] any time to see just the list of networks captured so far this session (paged with [a]/[l]; any other key returns to the live sweep without interrupting it).
Auto mode is capture-only β it doesnβt crack inline (so the sweep stays fast). Crack the collected .caps afterwards with cc:
CMD> cd /apps/karma
CMD> cc <ssid>.cap rockyou.txt
km auto deauth β deauth-assist (higher yield)
Plain km auto is passive β it only catches devices that are actively probing for a network (disconnected / searching). A phone sitting happily connected to its real router wonβt roam to your clone, so against already-connected devices the yield is low.
km auto deauth fixes that. The baited SSIDs come from probe requests β networks a device wants but isnβt on β so their APs usually arenβt in range to deauth. Instead, this mode scans for the APs that are present (the ones devices are actually connected to) and deauthenticates those during the sweep. Kicked devices disconnect and probe their whole saved list β including the absent SSIDs weβre cloning β so they discover the clone and complete the handshake. The status line shows BAIT+D when deauth is active (i.e. the scan found APs to kick). Itβs loud (it disrupts nearby networks), hence opt-in.
Performance: the engine is brought up once per sweep and re-targeted per SSID (no per-target WiFi restart), which keeps long hands-free runs stable.
Captive portals need a victim to interact with a web form, so they stay manual ([p] / km portal).
Harvest + fingerprint
Promiscuous probe-request sniff, channel-hopping 1β13. Two views ([v] toggles):
- HARV β SSID table: who-wants-what, sorted by number of distinct devices.
- DEVS β physical devices, clustered from randomized MACs by their probed-SSID set (PNL fingerprinting defeats MAC randomization when a device leaks a multi-SSID PNL). Shows vendor/type (OUI), PNL, and how many MACs collapsed into one device.
| Key | Action |
|---|---|
[v] | toggle HARV (nets) β DEVS (devices) |
| trackpad | select a row |
[a] / [l] | page |
[h] | WPA2 half-handshake bait on the selected target |
[p] | open AP + captive portal on the selected target |
[s] | save harvest + devices β /apps/karma/NNN.csv |
[c] | clear tables |
[q] | stop |
[s] writes a sequential NNN.csv (never overwrites) with two sections β [NETS] (ssid, devices, hits, rssi, channel) and [DEVICES] (id, vendor, type, macs, randomized, pnl_count, rssi, pnl).
WPA2 half-handshake bait β [h] / km hs
AL-ANQA stands up a manual rogue AP that clones the target SSID as WPA2. Because AL-ANQA is the AP, it generates its own ANonce and injects its own M1 β so it never needs to capture M1 over the air (an ESP32 canβt hear its own transmissions). A client that has the real network saved associates and replies with M2, whose MIC is keyed by the real password. With the known ANonce + the sniffed M2 you have a crackable half-handshake β no deauth, no real AP, WPA3/SAE immune.
The live screen shows the attack stages so you can see how far each client gets:
Prb β directed probe requests for our SSID
Ath β open-auth requests
Asc β association requests
M1 β M1 frames we injected
M2! β the client's reply captured β success
On M2!:
- A crackable capture is written to
/apps/karma/<ssid>.cap(beacon + M1 + M2, libpcap linktype 105) β open it in Wireshark or crack on a PC. Captures never overwrite: a second handshake for the same SSID is saved as<ssid>-1.cap,<ssid>-2.cap, β¦ The on-screen result shows the exact filename written. - Press
[c]to crack on-device: choose[1]SD wordlist (/apps/karma/wordlist.txt) or[2]built-in (100). A hit is shown and appended to/apps/karma/cracked.csv. A miss still leaves the.capon the card and tells you where it is.
The bait relies on the client associating to an AP that canβt ACK at the MAC layer. AL-ANQA sets its interface MAC to the rogue BSSID (and reads it back to guarantee they match) so the hardware ACKs the client; success varies by client. The stage counters tell you exactly where a given client stalls. The BSSID line shows
rnd(random/stealthed) orREAL(fell back to the deviceβs real MAC β still works, just identifiable).
To crack the saved .cap later (bigger wordlists, a whole directory of lists), use crack / cc.
Open captive portal β [p] / km portal
Brings up an open AP cloning the SSID + a captive portal for credential capture. The template picker ([p]) lists the shared built-ins (Generic / Google / Router) plus any .html in /apps/karma/portal/ and /apps/eviltwin/portal/ β so portals you already made for Evil Twin work here too. Captured credentials are written to /apps/karma/creds.csv on exit.
Files β /apps/karma/
| File | Contents |
|---|---|
<ssid>.cap (-1, -2β¦ if repeated) | half-handshake capture (beacon + M1 + M2); never overwritten |
cracked.csv | on-device crack results (ssid,password) |
connects.csv | auto-mode engagements (time,ssid,sta_mac,vendor,type) |
creds.csv | captive-portal credentials (ssid,user,pass) |
wordlist.txt | optional SD wordlist for [c] |
NNN.csv | saved harvest + device tables ([s]) |
portal/*.html | custom portal templates |
See also: Cap Cracker Β· Evil Twin Β· WPA Handshake