Sinisterly
sniff website not using https? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: sniff website not using https? (/Thread-sniff-website-not-using-https)



sniff website not using https? - SyntaxError - 08-21-2016

So i've found a website thats taking users e-mail & passwords but havent configured the ssl certs correctly (or not at all). I'm wandering if its possible to sniff their ports to record users login data. if so can someone direct me towards the right tutorials

Thanks


RE: sniff website not using https? - xulas - 09-28-2016

It is possible, but impractical unless you have a TAP-device installed on the physical location at hand. There are other ways to go about it, but it will require compromising the network of the host.


RE: sniff website not using https? - swatterhat - 10-02-2016

Sniffing maybe a bit difficult. Perhaps you can go SQL exploit.


RE: sniff website not using https? - Pleb - 10-19-2016

So no SSL enabled +1

Next step is to either MiTM an entire Nation(Look at North Korea for hints =P) Or you are just going to be stuck only capturing traffic on your local network you can use wireshark for this easily and just set a parameter to only include packets from that "IP" and you will be fine.

I would suggest against this ethically however it's your choice to do what you want.