Forum Replies Created
- AuthorPosts
akademikane
ParticipantI can modify but, which one do you recommend me because as you know to install something needs internet connection, so with fake captive protal no internet is there, any idea Diego ?
akademikane
ParticipantDieo I understand it, but what If we want when they click in the fake ap we give them a page so they enter the password and after it we gvie them a page you have to update this network and they click and get the backdoor ?
akademikane
ParticipantSo as I know fluxion is a program which checks if the entered password on the web is correct then they give access to the itnernet, is that right ?
akademikane
ParticipantIf the user is in a differnet network is that possible to downgrade https to http?
akademikane
ParticipantYes but why do I have to include a http when it downgrades https to http ? I’ve not tried it.
akademikane
ParticipantIt works now when I type ilesamples.com/formats/txt, but when I send a email to the target and they click on it so it will be https
akademikane
ParticipantI see that I forgot to type –mode transparent. THAT WORKS NOW.
But when i type zsecurity.org that goes to http good, and some other sites, but mozilla.org, and I type sample txt I see this
https://filesamples.com/formats/txt
this is https and doesn’t get downgraded to http, I try all https when needed to downloads something but doesn’t get http.
i don’t type manually https but I go to google .com and type sample txt sample pdf, they get downloads over https.
I also try bing.com they get downloaded over https again.akademikane
ParticipantI have ccleared browsing data, it works on http but not on https.
Also when I try to go to google.com and search for anything, it says invalid http request not working.akademikane
ParticipantNo Diego, still doesn’t work.
ettercap -Tq -M arp:remote -i wlan0 -S /192.168.1.103// /192.168.1.1//
mitmproxy/ iptables -t nat -A PREROUTING -p tcp –destination-port 80 -j REDIRECT –to-port 8080
./mitmdump -s sslstrip.py -s /opt/TrojanFactory/mitmproxy_script.pyNot working.
akademikane
ParticipantYes of course, this is the link that I got from network hacking conntinued that Zaid shared with us.
https://github.com/mitmproxy/mitmproxy/tree/v2.0.2/examples/complexI’ve cleared all the browsing data from the victim, but nothing happened.
Google.com uses hsts, but winzip and zsecurity not.
akademikane
ParticipantIt’s working for http, I can see data in wireshark, everything okay, but when I run sslstrip everything goes over https.
akademikane
ParticipantHelp me please.
akademikane
ParticipantEverything works with bettercap. I can sniff data from http, I can downgrade https to http, dns spoof and so on.
I am not able to sniff data from http://testphp.vulnweb.com/login.php, and in no http webiste.
I always enable port forward.akademikane
Participantas you can see that is working because it is changing.
akademikane
Participant- AuthorPosts