Remote Exploit Forums

Go Back   Remote Exploit Forums > BackTrack 4 (pre) Final > BackTrack 4 Howto


BackTrack 4 Howto Tutorials and Howtos about BackTrack 4 (NOT for requesting tutorials or how to do anything)

Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 07-14-2009, 09:14 AM
Junior Member
 
Join Date: Feb 2008
Posts: 21
Default

I used ettercap alone to crack my ssl pass on wellsfargo a while ago. I entered the pass with ie6 though! It just sent a fake security cert and then voila... I am guessing the new browsers require the use of sslstrip then? At what point in the browser upgrades did ettercap alone stop working?
Reply With Quote
  #12 (permalink)  
Old 07-15-2009, 12:03 AM
Member
 
Join Date: Oct 2006
Posts: 35
Default

nice tout i'm test on Firefox Setup 3.5 working no order any accept but test
on ie explorer 6 services update to sp3
give me message security look pic


my os win xp sp3 , but what about windows vista and win7 are working or not
Reply With Quote
  #13 (permalink)  
Old 07-15-2009, 07:07 AM
Just burned his ISO
 
Join Date: Jul 2009
Posts: 2
Default

Awesome Tutorial
__________________
root:/yourmom/pants
Reply With Quote
  #14 (permalink)  
Old 07-15-2009, 11:59 AM
Junior Member
 
Join Date: Jul 2009
Posts: 7
Default

Quote:
Originally Posted by onryo View Post
.... Is SSLstrip (not on a rouge AP) still ULTRA slow?

Onryo
I have tested sslstrip 0.2 a couple times on my own network with mostly positive and fast results.

However there has been a few times where I had two different problems (on different trys):

One of them being that the victim connection just died. I forgot the check if it was only the HTTP traffic or the entire connection

The other problem was that I got the "This connection is unsecure bla bla bla" SSL warning thing on the victim computer.
Reply With Quote
  #15 (permalink)  
Old 07-16-2009, 08:29 PM
Junior Member
 
Join Date: Feb 2008
Posts: 5
Default

Great tutorial!! Worked a charm.

Only thing is, when I go back after having logged in, it comes up with the unsecure certificate malarky.
Reply With Quote
  #16 (permalink)  
Old 07-25-2009, 12:29 PM
Just burned his ISO
 
Join Date: Oct 2008
Posts: 2
Default

awesome tut but i tried it with ubuntu and what happened it was realy strange when i started to sniff with ettercap i checked my other pc went to paypal and it was giving me the message it works! from the php thing:S i tried all the sites but i got always the same:S.
and now i cant see any site:S please help
Reply With Quote
  #17 (permalink)  
Old 07-25-2009, 08:00 PM
smithwaysecurity's Avatar
Just burned his ISO
 
Join Date: Jun 2009
Location: Canada
Posts: 2
Default

hey everyone if looking for a tutorial check out bt France community the guy named benjy did up a nice on on sslstrip
Reply With Quote
  #18 (permalink)  
Old 07-26-2009, 01:24 AM
Junior Member
 
Join Date: Jun 2009
Posts: 12
Default

Ive been testing ettercap at work and I will agree that it wasnt very "seamless". Only 20% of the computers had to accept the fake SSL cert before ettercap would grab the passwords.

Not sure if there is any way around this.

Great vid tho!
Reply With Quote
  #19 (permalink)  
Old 07-26-2009, 10:16 PM
Junior Member
 
Join Date: Jun 2009
Posts: 26
Default

nice tutorial, keep up the good work
Reply With Quote
  #20 (permalink)  
Old 07-27-2009, 03:31 PM
Just burned his ISO
 
Join Date: Jul 2009
Posts: 2
Default

good God! works great..

how to tweak arp so the connection will not slow while MITM attack is enable?

is anybody know?
Reply With Quote
Reply

Bookmarks

Tags
g0tmi1k, https, ssl, sslstrip

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 04:02 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2