Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


sniff website not using https? filter_list
Author
Message
sniff website not using https? #1
So i've found a website thats taking users e-mail & passwords but havent configured the ssl certs correctly (or not at all). I'm wandering if its possible to sniff their ports to record users login data. if so can someone direct me towards the right tutorials

Thanks

Reply

RE: sniff website not using https? #2
It is possible, but impractical unless you have a TAP-device installed on the physical location at hand. There are other ways to go about it, but it will require compromising the network of the host.

Reply

RE: sniff website not using https? #3
Sniffing maybe a bit difficult. Perhaps you can go SQL exploit.

Reply

RE: sniff website not using https? #4
So no SSL enabled +1

Next step is to either MiTM an entire Nation(Look at North Korea for hints =P) Or you are just going to be stuck only capturing traffic on your local network you can use wireshark for this easily and just set a parameter to only include packets from that "IP" and you will be fine.

I would suggest against this ethically however it's your choice to do what you want.

Reply