Sinisterly
Ettercap Man In The MIddle Attack + SSL Strip - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Computers (https://sinister.li/Forum-Computers)
+--- Forum: Operating Systems (https://sinister.li/Forum-Operating-Systems)
+--- Thread: Ettercap Man In The MIddle Attack + SSL Strip (/Thread-Ettercap-Man-In-The-MIddle-Attack-SSL-Strip)

Pages: 1 2 3 4


RE: Ettercap Man In The MIddle Attack + SSL Strip - papamoney - 06-20-2011

(04-16-2011, 04:55 PM)lagann Wrote:
(04-16-2011, 03:56 PM).LiT Wrote:
(04-16-2011, 01:38 AM)lagann Wrote: if we don't use ssl-strip, the browser will said there is smthing wrong with the certificates..
:8-s:
DOS Attacking with Ettercap---> I will try thiss....thank's :thumbs:

NP glad you like, I can add more to this guide too like how to redirect victims to different websites of your choosing or how to change all the pictures the victim sees as they browse the web if u want?

By the way the victims computer will still get a "are you sure you want to proceed anyway" message even if you use ssl strip. We can sucesfully strip the ssl out but we still dont have the legit ssl certificate. There are ways to make your own legit ones so that message does not prompt the user though I think.

The message differs depending on what browser the victim is using, nevertheless this works because most people will just click proceed anyway. Just make sure to use backtrack not another distro..for this guide anyways.

:rofl:....I'm not saying that I use ur ssl-strip ^_^' ...
but I like ur dos attcks :thumbs:

how to redirect victim to other site...?
also we can use driftnet..this tool allow you to view what ovictim is viewing..Smile



RE: Ettercap Man In The MIddle Attack + SSL Strip - .LiT - 06-30-2011

(06-20-2011, 12:49 PM)papamoney Wrote:
(04-16-2011, 04:55 PM)lagann Wrote:
(04-16-2011, 03:56 PM).LiT Wrote:
(04-16-2011, 01:38 AM)lagann Wrote: if we don't use ssl-strip, the browser will said there is smthing wrong with the certificates..
:8-s:
DOS Attacking with Ettercap---> I will try thiss....thank's :thumbs:

NP glad you like, I can add more to this guide too like how to redirect victims to different websites of your choosing or how to change all the pictures the victim sees as they browse the web if u want?

By the way the victims computer will still get a "are you sure you want to proceed anyway" message even if you use ssl strip. We can sucesfully strip the ssl out but we still dont have the legit ssl certificate. There are ways to make your own legit ones so that message does not prompt the user though I think.

The message differs depending on what browser the victim is using, nevertheless this works because most people will just click proceed anyway. Just make sure to use backtrack not another distro..for this guide anyways.

:rofl:....I'm not saying that I use ur ssl-strip ^_^' ...
but I like ur dos attcks :thumbs:

how to redirect victim to other site...?
also we can use driftnet..this tool allow you to view what ovictim is viewing..Smile
Ok i'm adding to the guide how to dns spoof and change the pictures people see using Ettercap.



RE: Ettercap Man In The MIddle Attack + SSL Strip - changeusername123 - 07-07-2011

Great thread thanks man..


RE: Ettercap Man In The MIddle Attack + SSL Strip - akitta - 09-04-2011

Excellent tutorial .LIT i'm going to give you rep i think you deserve it for this. ettercap and sslstrip do work across wifi aswell,


RE: Ettercap Man In The MIddle Attack + SSL Strip - .LiT - 09-06-2011

(09-04-2011, 11:23 PM)akitta Wrote: Excellent tutorial .LIT i'm going to give you rep i think you deserve it for this. ettercap and sslstrip do work across wifi aswell,

Thanks! Hmm really you got it to work well with wifi? I've never got it to work correctly wireless for some reason. How do you do it? Do you just specify your wireless interface when you run ettercap? -i wlan0 or something like that?


RE: Ettercap Man In The MIddle Attack + SSL Strip - .LiT - 09-06-2011

(09-04-2011, 11:23 PM)akitta Wrote: Excellent tutorial .LIT i'm going to give you rep i think you deserve it for this. ettercap and sslstrip do work across wifi aswell,

Thanks! Hmm really you got it to work well with wifi? I've never got it to work correctly wireless for some reason. How do you do it? Do you just specify your wireless interface when you run ettercap? -i wlan0 or something like that?


RE: Ettercap Man In The MIddle Attack + SSL Strip - 1234hotmaster - 09-06-2011

i forgot to read this thread before cause i never had access to someone else's wifi before.

IM GOING TO REP FK YOU .LiT FOR THIS AMAZING GUIDE AND FIXING THE ETTERCAP CONFIGURATION GUIDE Angry


RE: Ettercap Man In The MIddle Attack + SSL Strip - 1234hotmaster - 09-06-2011

i forgot to read this thread before cause i never had access to someone else's wifi before.

IM GOING TO REP FK YOU .LiT FOR THIS AMAZING GUIDE AND FIXING THE ETTERCAP CONFIGURATION GUIDE Angry


RE: Ettercap Man In The MIddle Attack + SSL Strip - akitta - 09-06-2011

(09-06-2011, 03:26 AM).LiT Wrote:
(09-04-2011, 11:23 PM)akitta Wrote: Excellent tutorial .LIT i'm going to give you rep i think you deserve it for this. ettercap and sslstrip do work across wifi aswell,

Thanks! Hmm really you got it to work well with wifi? I've never got it to work correctly wireless for some reason. How do you do it? Do you just specify your wireless interface when you run ettercap? -i wlan0 or something like that?

Yeh just specify which interface your using (ie -i wlan0) then you have to put in the router and target ip-add (like this 'ettercap -T -Q -M arp:remote -i wlan0 /192.168.1.254/ /192.168.1.89/ -P remote_browser') OR if your using ettercap -G (GUI) just search HOSTS

i've just seen this aswell for configuring ettercap to not throw up fake certificates (don't know if it works)
Ettercap has been capable of sniffing HTTPS usernames and passwords for years. It uses a fake certificate that's easy to spot when visiting 'important' sites like online banking etc. There are two lines you need to uncomment in ettercaps config file.
So, don't accept new certificates ('add exception' in Firefox) without reading them!
This could be useful beacause the only reason i don't use ettercap is because of it throwing up certificates when sniffing.





RE: Ettercap Man In The MIddle Attack + SSL Strip - akitta - 09-06-2011

(09-06-2011, 03:26 AM).LiT Wrote:
(09-04-2011, 11:23 PM)akitta Wrote: Excellent tutorial .LIT i'm going to give you rep i think you deserve it for this. ettercap and sslstrip do work across wifi aswell,

Thanks! Hmm really you got it to work well with wifi? I've never got it to work correctly wireless for some reason. How do you do it? Do you just specify your wireless interface when you run ettercap? -i wlan0 or something like that?

Yeh just specify which interface your using (ie -i wlan0) then you have to put in the router and target ip-add (like this 'ettercap -T -Q -M arp:remote -i wlan0 /192.168.1.254/ /192.168.1.89/ -P remote_browser') OR if your using ettercap -G (GUI) just search HOSTS

i've just seen this aswell for configuring ettercap to not throw up fake certificates (don't know if it works)
Ettercap has been capable of sniffing HTTPS usernames and passwords for years. It uses a fake certificate that's easy to spot when visiting 'important' sites like online banking etc. There are two lines you need to uncomment in ettercaps config file.
So, don't accept new certificates ('add exception' in Firefox) without reading them!
This could be useful beacause the only reason i don't use ettercap is because of it throwing up certificates when sniffing.