12
Sniffing HTTPS in LAN using ARP Poisoning Adithyan AK Balaji S

Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Embed Size (px)

Citation preview

Page 1: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Sniffing HTTPS in LAN using ARP Poisoning

Adithyan AK Balaji S

Page 2: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

HTTP, HTTPS & HSTS

• Hyper Text Transfer Protocol (HTTP)

• Hyper Text Transfer Protocol Secured (HTTPS)

• HTTPS Strict Transport Security (HSTS)

Page 3: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

HTTP Unencrypted Username Passwords

Page 4: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

HTTPS Ecnrypted Traffic

Page 5: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Breaking HTTPS

• SSL Strip & Bettercap

• Attacker acts as proxy between Victim and server.

• Breaking HSTS

• What if we can sniff ?

Page 6: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Sniffing HTTPS Data

• Convert the attacker machine into a router.

• Enable IP forward to intercept the network traffic.

Page 7: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Hooking up the Target

• Scan for hosts in the network.

• Identify the target with MAC / Social Engineering / HTTP Data

Page 8: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

ARP Poisoning

• Send n number of ARP Request

• Link Attacker’s MAC with Victim’s IP

• Ettercap, ARPspoof, MITMf.

Page 9: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Configuring Proxy Listeners on LAN

• Setup proxy listener on PORT 80 & 443

• Burp suite, ZAP, BeeF XSS Framework.

Page 10: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to
Page 11: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

Sniffing HTTPS

Page 12: Sniffing HTTPS in LAN using ARP Poisoning · HTTP, HTTPS & HSTS •Hyper Text Transfer Protocol ... ettercap 0.8.2 Filters Logging Plugins Info Description Add to Target 1 Add to

$echo Queries?

Reach us @

[email protected]

[email protected]