Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. ESP
  3. WiFiDuck

WiFiDuck

MITC++1.1.0

A wireless keystroke injection attack platform that emulates a USB keyboard and is managed via WiFi.

Visit WebsiteGitHubGitHub
3.1k stars455 forks0 contributors

What is WiFiDuck?

WiFi Duck is an open-source platform that performs keystroke injection attacks by emulating a USB keyboard. It allows users to remotely send automated keystroke sequences to a target computer via WiFi, demonstrating the security risks of trusted USB devices. The project includes both hardware and software components, supporting DIY builds or pre-assembled devices.

Target Audience

Security researchers, penetration testers, and educators who want to learn about or demonstrate BadUSB attacks and USB-based vulnerabilities in a controlled environment.

Value Proposition

Unlike traditional BadUSB tools, WiFi Duck offers wireless management through a web interface, eliminating the need for physical media or installed software. Its open-source nature and hardware flexibility make it accessible for customization and educational use.

Overview

Wireless keystroke injection attack platform

Use Cases

Best For

  • Learning about BadUSB attacks and keystroke injection techniques
  • Conducting authorized penetration tests on USB security
  • Building custom wireless keystroke injection devices
  • Educational demonstrations of USB-based vulnerabilities
  • Automating repetitive keyboard tasks for testing purposes
  • Developing and testing Ducky Script payloads in a wireless environment

Not Ideal For

  • Large-scale penetration testing operations requiring device management or integration with professional frameworks
  • Covert security assessments where default WiFi credentials (SSID 'wifiduck', password 'wifiduck') could raise alarms
  • Dynamic, interactive attacks needing real-time keyboard feedback or immediate script adjustments
  • Users lacking hardware soldering skills or experience with microcontroller programming and flashing

Pros & Cons

Pros

Remote Web Interface

Offers wireless control via a built-in web server over WiFi, allowing script management without physical access or additional software, as highlighted in the web-based interface feature.

Ducky Script Compatibility

Uses the industry-standard Ducky Script language from Hak5, enabling easy adoption of existing scripts and resources for keystroke injection, as noted in the scripting basics section.

Hardware Flexibility

Supports DIY builds with common boards like Atmega32u4 and ESP8266, or pre-assembled options like Malduino W, providing versatility for different user needs, as detailed in the hardware sections.

Over-the-Air Updates

Allows firmware updates via WiFi without physical reflashing, improving maintainability and ease of use, mentioned in the flash software section for ESP8266.

Cons

Complex DIY Setup

Requires soldering, precise pin connections between two microcontrollers, and separate flashing processes, which can be error-prone and time-consuming, as admitted in the DIY hardware and flash software sections.

Limited Attack Vectors

Focused solely on keystroke injection via USB emulation, lacking support for other USB-based attacks like storage emulation or HID spoofing, which limits its scope compared to broader security tools.

Documentation Complexity for Customization

Adding new keyboard layouts involves manual coding, testing, and modifying source files, as described in the translate keyboard layout section, which can be daunting for non-developers.

Frequently Asked Questions

Quick Stats

Stars3,101
Forks455
Contributors0
Open Issues16
Last commit3 years ago
CreatedSince 2019

Tags

#hacktoberfest#esp8266#hardware-security#hid#arduino#pentesting

Built With

E
ESPAsyncWebServer
s
spiffs
C
C++
E
ESP8266
A
Arduino

Links & Resources

Website

Included in

ESP2.3k
Auto-fetched 4 hours ago

Related Projects

ESP8266 DeautherESP8266 Deauther

Affordable WiFi hacking platform for testing and learning

Stars14,890
Forks2,759
Last commit1 year ago
ESP32MarauderESP32Marauder

A suite of WiFi/Bluetooth offensive and defensive tools for the ESP32

Stars11,674
Forks1,355
Last commit1 day ago
ESP8266 Beacon SpamESP8266 Beacon Spam

Creates up to a thousand WiFi access points with custom SSIDs.

Stars1,333
Forks231
Last commit1 year ago
DeauthDetectorDeauthDetector

Detect deauthentication frames using an ESP8266

Stars960
Forks203
Last commit2 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub