I have been wondering if it is possible to make a fake ap with airbase-ng and instead of capturing packets, i would be changing them, so I would redirect a client connected to the fake ap to any website I choose. for example, someone connects to my fake ap and clicks a login button but instead of going to the real page they are sent a packet containing a fake login page that steals passwords.

You are talking about Evil Twin (Search it)


It's possible. I already managed to redirect my web browser to another webpage using DNS packet injection. However, I think it may be harder if the victim is using https since he's excepting a certificate to authentify the other side.

