Ten Years of Service
Posts: 4
Threads: 2
sniff website not using https? 08-21-2016, 12:47 AM
#1
So i've found a website thats taking users e-mail & passwords but havent configured the ssl certs correctly (or not at all). I'm wandering if its possible to sniff their ports to record users login data. if so can someone direct me towards the right tutorials
Thanks
•
Ten Years of Service
Posts: 21
Threads: 1
RE: sniff website not using https? 09-28-2016, 08:54 AM
#2
It is possible, but impractical unless you have a TAP-device installed on the physical location at hand. There are other ways to go about it, but it will require compromising the network of the host.
•
Ten Years of Service
Posts: 166
Threads: 10
RE: sniff website not using https? 10-02-2016, 03:27 AM
#3
Sniffing maybe a bit difficult. Perhaps you can go SQL exploit.
•
Nine Years of Service
Posts: 4
Threads: 0
RE: sniff website not using https? 10-19-2016, 10:14 AM
#4
So no SSL enabled +1
Next step is to either MiTM an entire Nation(Look at North Korea for hints =P) Or you are just going to be stuck only capturing traffic on your local network you can use wireshark for this easily and just set a parameter to only include packets from that "IP" and you will be fine.
I would suggest against this ethically however it's your choice to do what you want.
•