NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

wireless.nix (3477B)


      1 # modules/features/pentest/wireless.nix — 802.11 and on-the-wire capture.
      2 # Off by default. `daemon.pentest.wireless.enable = true;`
      3 #
      4 # Bluetooth, RFID/NFC and software-defined radio are NOT here — they are their
      5 # own category (radio.nix), because this one is about a wifi adapter in monitor
      6 # mode and that one is about an SDR dongle or a Proxmark. Enabling one should
      7 # not drag in the other's drivers and GUIs.
      8 #
      9 # Most of this needs a card that supports monitor mode and injection, and all
     10 # of it needs root. `airmon-ng start wlan1` will fight NetworkManager for the
     11 # interface; `airmon-ng check kill` is the usual answer.
     12 { lib, ... }:
     13 (import ./_sets.nix { inherit lib; }) {
     14   name = "wireless";
     15   description = "wifi attacks, rogue APs and packet capture";
     16   default = false;
     17 
     18   packages = pkgs: with pkgs; [
     19     # The classics
     20     aircrack-ng
     21     hcxtools
     22     hcxdumptool # PMKID capture, the modern first move
     23     bettercap
     24 
     25     # Drivers of the above
     26     wifite2 # `wifite`: wraps aircrack/reaver/bully/hcx into one attack loop
     27     airgeddon # the menu-driven equivalent, when you want to see each step
     28 
     29     # WPS
     30     reaverwps-t6x # `reaver` and `wash`, the t6x fork (the maintained one)
     31     bully
     32     pixiewps # offline WPS pin recovery
     33 
     34     # WPA handshake and enterprise
     35     cowpatty # cowpatty, genpmk
     36     asleap # LEAP/PPTP MS-CHAPv2
     37 
     38     # Deauth, beacon flood, rogue AP
     39     mdk4
     40     hostapd # the honest way to stand up a rogue AP
     41 
     42     # Interface wrangling
     43     iw
     44     wirelesstools # iwconfig, iwlist — older tools some scripts still call
     45     macchanger
     46     horst # a quick 802.11 top(1)
     47 
     48     # Capture
     49     kismet
     50     termshark
     51     tcpdump
     52     # The full wireshark, not wireshark-cli: gui.nix installs this same
     53     # attribute, and two DIFFERENT wireshark builds both ship androiddump,
     54     # dumpcap and friends — a profile collision when both categories are on.
     55     # Identical paths merge fine. It provides `tshark` for headless use.
     56     wireshark
     57   ];
     58 
     59   expectedBins = [
     60     "aircrack-ng" "airmon-ng" "airodump-ng" "aireplay-ng"
     61     "hcxpcapngtool" "hcxhashtool" "hcxdumptool" "bettercap"
     62     "wifite" "airgeddon"
     63     "reaver" "wash" "bully" "pixiewps"
     64     "cowpatty" "genpmk" "asleap"
     65     "mdk4" "hostapd"
     66     "iw" "iwconfig" "iwlist" "macchanger" "horst"
     67     "kismet" "termshark" "tcpdump" "tshark"
     68   ];
     69 
     70   extraConfig = { pkgs, lib, ... }: {
     71     # As in gui.nix: the group and the dumpcap capability wrapper, without
     72     # which capture needs full root.
     73     #
     74     # `package` is set at a WEAKER priority than gui.nix's mkDefault (1000) on
     75     # purpose. Two mkDefaults are not interchangeable here: `types.package`
     76     # merges with mergeEqualOption, which compares definitions with `==`, and
     77     # `==` on two derivations compares their `override`/`overrideAttrs`
     78     # functions and is therefore false even for the same store path. So two
     79     # equal-priority definitions are a hard "defined multiple times" error the
     80     # moment `gui` and `wireless` are both on. The ladder makes gui win and
     81     # leaves this one effective when gui is off.
     82     #
     83     # It must be the full wireshark either way: this category installs that
     84     # attribute in `packages`, and the module's own default (wireshark-cli)
     85     # would be a SECOND package owning bin/tshark and bin/dumpcap.
     86     programs.wireshark = {
     87       enable = lib.mkDefault true; # bool merges when the values are equal
     88       package = lib.mkOverride 1500 pkgs.wireshark;
     89     };
     90   };
     91 }