PineAP is an effective, modular rogue access point suite for the WiFi Pineapple. In some ways it can be seen as the next-generation Karma, but as you’ll see it’s a whole lot more.

MK5 Karma

Since the original WiFi Pineapple Mark 1, Karma has played a key role in attracting clients. MK5 Karma now takes on this important role and then some, supporting a host of additional PineAP modules intended to effectively host spoofed Access Points, or honeypots. At the core of this feature is the trick of quite simply replying to probe requests with appropriately crafted probe responses.

For example, if a Client device (like a phone or laptop) sends out a probe request for an Access Point (AP) with the SSID “ACME Corporate LAN”, the MK5 Karma module will reply with an appropriately crafted probe response mimicking the SSID “ACME Corporate LAN”.

While this simple call and response trick is effective on many devices, it becomes even more potent when coupled with the formidable host of PineAP modules like Dogma, Beacon Response, Auto Harvester, Recon Mode and Deauth.


If Karma is the passive listening type, Dogma is it’s direct and aggressive sibling.

The Dogma PineAP module is intended to reinforce the MK5 Karma attack by advertising the spoofed Access Points, or honeypots. This is achieved by transmitting appropriately crafted beacon frames (packets) at uncommonly high rates for WiFi equipment. These frames mimic the networks defined by SSID values in the PineAP SSID Pool. This pool of network names are either defined by the penetration tester, or automatically collected by the Auto Harvester module. More on that in a bit.

For example the WiFi auditor is on an engagement for the ACME Corporation, they might specifically define SSID names derived from ACME corporate and branch offices.

A powerful Dogma feature is its ability to be configured with specific Source and Target MAC addresses. The Target MAC is that of the nearby clients or devices. If a target MAC address is specified, typically only that client (station) will observe the beacon frame advertising the honeypot.

The default target of FF:FF:FF:FF:FF:FF (otherwise known as Broadcast) makes these beacons visible to all nearby devices. This is very useful if the penetration tester is contracted to perform a WiFi audit on only a specific individual within the company.

The default Dogma configuration is to use the MAC address of the WiFi Pineapple as the beacon’s Source address. You may be wondering, why spoof the source address? The answer becomes apparent when using multiple WiFi Pineapples on an engagement. By spoofing the source address of Dogma’s beacons, the tester can use additional WiFi Pineapples to direct clients to a central WiFi Pineapple, either increasing the WiFi coverage area, or increasing the Dogma beacon throughput.

Throughput wise the Dogma module will transmit beacons at an incredibly high rate of around 400 per second. This is about 200-400 times more than most typical access points, which allows the WiFi Pineapple to mimic hundreds of SSIDs at once. The rate can be further increased by choosing Aggressive mode from the Dogma settings, however in our tests we’ve found the Normal mode to be effective even with very large SSID pools.

Beacon Response

The Beacon Response module of PineAP brings the siblings Karma and Dogma together for a killer combination.

Similar to how MK5 Karma responds to a potential clients Probe Request with an appropriately crafted Probe Response, the Beacon Response module responds to the potential client with appropriately crafted beacons targeted solely at them. This reinforces the legitimacy of the spoofed network without causing broadcast beacons which may otherwise be picked up by other devices. As opposed to Dogma in its default “broadcast” state, beacon response only responds to the potential client, and only when that client makes a probe request.

For example, if a potential client transmits probe requests looking for an Access Point with the SSID “ACME Corporate LAN” – MK5 Karma will reply with a probe response using the SSID “ACME Corporate LAN”. Additionally, if the Beacon Response module is enabled, several targeted beacon frames advertising the Access Point “ACME Corporate LAN” will be transmitted for a period.

Much like Dogma, these beacon frames use the Source address configured, so the feature can be used in conjunction with multiple WiFi Pineapples during an audit. Since the Target address will always be that of the potential client transmitting the probe requests, the WiFi Pineapples beacon “responses” will typically only be observed by the potential client.

Auto Harvester

Auto Harvester is like War Driving with the petal to the metal in reverse.

Instead of gathering SSID names from the Beacon frames advertised by Access Points, Auto Harvester collects them from the Probe Requests leaking from the potential clients. These SSID names are often telling of our clients – who they work for, what vendors they meet with, even where they like to get coffee. The network names collected by Auto Harvester get added to the PineAP SSID Pool for use by Dogma. This silent module transmits nothing and can be used alone to perform passive reconnaissance on an area. Running Auto Harvester in a crowded area provides a shocking look at how much data is freely flowing from modern devices – ready to be exploited by the PineAP suite.

For example, if a potential client device transmits a probe request for an Access Point with the SSID “ACME Corporate LAN”, the Auto Harvester module will save “ACME Corporate LAN” to the SSID Pool for later use. If Dogma is currently running, it will broadcast that beacon to either a specified target or broadcast, meaning all devices in the vicinity. Suddenly a single frame leaked from one individual causes the WiFi Pineapple to assume that networks identity for all others in the area.

Recon Mode

Unlike traditional War Driving, whereby the auditor passively listens for beacons being advertised by Access Points to paint a picture of the surrounding WiFi landscape, the WiFi Pineapple’s Recon Mode goes one giant step further.

By monitoring channels for both beacons and data activity, Recon Mode paints a more complete picture by combining Access Points with their respective clients. This is huge. With the WiFi landscape displayed in this manner, a tester can quickly identify potential targets from Recon Mode and immediately take action with PineAP. Recon Mode directly interfaces with the rest of the PineAP suite, enabling targeted attacks on both the clients and access point level with contextual actions with just a click.

If PineAP is the ammunition, Recon Mode is the battlefield.


From the “Pinejector” back-end to the Recon Mode front-end, the modular nature of the PineAP suite is at the core of the WiFi Pineapple’s success. MK5 Karma, Dogma, Beacon Response, Auto Harvester, and Recon Mode are only the beginning. It’s been a big year for WiFi Pineapple development, and we’re proud of the powerful Man-In-The-Middle platform we’ve pioneered. PineAP makes the most of the unique WiFi Pineapple Mark V hardware, and we’re eager to show you how far it can go.

The Next-Gen Rogue Access Point: PineAP

1 Comment

  • Autorijles Delft

    I was wondering if you ever thought of changing
    the layout of your blog? Its very well written; I love what youve got to say.
    But maybe you could a little more in the way of content so people could connect with it
    better. Youve got an awful lot of text for only having one or 2 pictures.

    Maybe you could space it out better?

  • banjamondsink

    Robert Smoley, engineering and healthcare

    Some masses of our modernistic gild give care to throw a modification nigh the style we bouncy. They get a determination in training, gather cognition and underdeveloped freshly shipway of improving the choice of our lives. Robert Smoley is unitary of those persons, WHO apprehended disbursement his metre investing in fresh technologies. He collected a vast receive in a slap-up list of body process fields, equivalent living thing communications, act constructions, modeling, or Net marketing, to mention good a pair of then, for which he has created utile country of the prowess technologies. His more than xxx geezerhood of undergo as a lawyer, helped him as easily to be an effective leader in the managerial team of whatever of the companies he created.
    Belike unitary of his just about noteworthy instauration was the telemedicine system. It is a revolutionary approximation well-nigh receiving health check visits and advices, regarding whatever medical examination issue you mightiness wealthy person. MD Live, as the program is called, crack aesculapian consultations all over the ring or with the aid of online telecasting flowing. Thus, a patient role does non motive to exit internal or office, does non necessitate to accept his children come out of school, or hold in dateless queues, in place to do good from a doctor’s advice. Done MD Live, Rober Smoley brought a groovy batch of easing to a huge turn of patients who, for several reasons, could not get through the doctor’s bureau.
    Health 2.0, the accompany started by Robert Smoley, which brought to the public the MD Alive service, is alone in the public. In that respect isn’t whatever other organization that holds so much a elaborate database of patients, patients’ records, doctors, medical prescriptions, and the unwellness and wellness story of every patient role. From the desire to take this organisation available for an level enceinte bit of people, the accompany signed a partnership with Google, which is a dandy dance step in expanding the system of rules.
    Robert Smoley’s melodic theme of instauration something similar MD Inhabit brings was More than welcomed by the spacious consultation. He didn’t also make and effective system, simply too an low-priced one, existence even cheaper than pinch upkeep. It agency that, owed to his groundbreaking ideas and implication, everybody fire welfare from professional person health check care, at low-pitched prices and in a selfsame effective mode. It surely represents the future of our health check maintenance. And due to dedicated people, like Robert Smoley, we rear be certain that our later bequeath flavor a Lot improve than it does nowadays.

    Projects that tooshie economize our lives
    Robert Smoley
    The aesculapian tending scheme is one and only of the most crucial aspects of our lives. We neediness to welfare from just wellness care, and we lack to deliver a speedy entree to doctors in lawsuit the wellness publication aggravates. Simply what if we are ineffective to compass the doctor’s situation because we are too unbalanced or bear to tipsy schedules? Non to bring up that when it comes to the guard of our children zilch is overly firm. Henry M. Robert Smoley though just about wholly of these scenarios and came up with the virtually efficient solution, below the frame of MD Live, a telemedicine serve.
    Robert Smoley is a reputable lawyer, having a expectant count of age in this activeness orbit. But it is besides a successful entrepreneur, putt his skills and cognition not into his benefits, simply for the interests of people. He is the Almighty of multiple discipline breakthroughs and services, meant to take a different view and alteration the fashion we are victimised to doing things. Cyberspace marketing, ware ontogenesis and packaging, living thing communications, human action constructions, they completely wear the impression of Henry Martyn Robert Smoley and his awing projects. And these projects never remained at the condition of thetheory, as they are successfully applied in virtual activities as well, relieving masses of heavy to negociate tasks.
    MD Alive was created by Henry Martyn Robert Smoley from the trust to bestow the benefits of the latest engineering with the advantages of business health check wish. He knows fair how important health is to us and how important is to capture a unspoilt doctor’s advice regarding a bothering medical exam military issue. With the MD Lively service, completely the fundamental interaction with the medico of your choice is through by speech sound or computer, through and through the supporter of bouncy video flowing. For a real affordable sum, you prat touch a touch on from the consolation of your house, from a hotel room, or level from your office, whenever you motivation approximately medical checkup assistance or don’t flavor expert.On that point is no longer the want to result your locating and wait until a sophisticate derriere have you into his function. Scarcely telephone call or bow your problem online, and you bequeath be contactedat the shortest notice by a physician that has the suited competencies to slew with your wellness progeny.
    Owed to Henry Martyn Robert Smoley’s innovational and serious-minded plan, anyone fire enjoy low-cost medical examination services anyplace and anytime. So many quenched populate who already put-upon the programme nation that this represents the future of health care. And since anyone wishes to savor animation More and delay trivial at queues in medical examination cabinets, we might upright think their statement is dependable.

    Populate that engagement for a ameliorate aliveness select
    Our lives could non experience been this secure, well-fixed and fulfilling if it weren’t for about masses that dedicate their clock time and effort to name a convert. Nonpareil of those persons is Robert Smoley, WHO took the benefits of modernistic applied science and off it in our favour. He is in never-ending look for for a improve manner to amend the fashion we know and, yet about important, the way of life our wellness and well-existence is hardened. Without his projects, our New company would throw been a mess less evolved.
    Robert Smoley placed his impress on multiple breakthroughs, which knotty the use of the latest technologies. The residential constructions sector, mathematical product development, modeling, Internet credit entry bill of fare processing and more enjoyed the implications of Henry Martyn Robert Smoley. Just plausibly his scoop accomplishment has been in the medical checkup and healthcare human beings. He created and implemented MD Live, an online health care program, which permits doc appointments without departure your home base. With elementary subscriptions, you tail range through and through an entire listing of physicians, on multiple medical exam specialties, whenever you have got a problem. You bequeath be able to verbalise with your furbish up on thephone or by having a telecasting conference, done a picture flowing meshing.
    No penury to proceeds your children away of the sign when they are crazy. No motivation to tally out from work out if you experience a problem. And no want to quell in perpetual queues and crowded postponement room, in collaboration with patients that might be sick. You could evening be come out of town and yet be able-bodied to hear your trusted Dr. with the assist of MD Bouncy. It is for sure a benefit that will switch our lives and the way of life we have Greco-Roman deity care. You used to walking into a doctor’s waiting board for a trouble and walking kayoed with the virus of a severe flu, caught from a cough affected role who was wait in that location as easily. So non entirely Robert Smoley’s peachy picture brought consolation to our lives, but it also improved the calibre of our health, holding us good from whatever other voltage wellness threats.
    It offers fantabulous solutions for people with engaged schedules at the well-nigh low-cost clock time. Most of us mold during the schedules of doctors. So remunerative them a confab way skipping work, flush fetching a twenty-four hour period off, belligerent traffic, which bequeath atomic number 82 to a zealous lot of inconveniences that leave eventually pass water you dismiss sightedness your doctors. So whatsoever government issue you mightiness have, arse catch severer and campaign you unhappiness. So bury completely of that and equitable pluck up the telephone set or log onto your computing machine each fourth dimension you motivation to consider a fix.

    robert smoley
    robert smoley

  • Rosetta

    Drawing on his earlier experimentation together with his homemade report-chopping machines, Paul added
    an additional playback head to the recorder.

  • Amelie

    I like what you guys are up too. This kind of
    clever work and reporting! Keep up the superb works guys I’ve incorporated you
    guys to my own blogroll.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>