Added: 3 years ago
From: xplagu3
Views: 41,524
Sort by time | Sort by thread (beta)

Link to this comment:

Share to:

All Comments (27)

Sign In or Sign Up now to post a comment!
  • NOT WORKING..............THOUGH I HAVE TRIED ON MY OWN COMPUTER

  • Or 3.

  • Nice vid. What distro is this?

  • @blacksiddis

    Backtrack 4.

  • post a link to your etter.conf file plz. and nice vid

  • This only works if the victim accepts the fake ssl cert.

  • need a novelty? gruber@email.ru

  • dosent work for me after i logged in nothing happen have tried the attack against several other computers and im using wlan0 plz help me

  • to arppoison an entire wlan into thinking you're the router you can use: "ettercap -TqM arp:remote // //" just found that out.

  • hah, i wouldn't call the user an unsuspecting user.

  • Hi, i was wondering if someone could help me in solving this problem i have with SSLstrip

    When i run the SSLstrip script it gives me the following error:

    ImportError: No module named StrippingProxy

    I'm using Linux Ubuntu

    thanks in adavance

  • what is the song ?? GROUP ? title ?? thanks ;) VERY GOOD post !

  • Cheers. Song is Fuck Authority by Pennywise

  • Damn. Thanks :)

    I thought google was smart about security, and you just jacked your own password.

  • No, you are incorrect. Google is smart about security it would be the end user that would be the fault of this attack. In this case the user was presented with a warning about self signed certificate and possible security risk, but chose to ignore it as most people would. SSL3/TLS1 is employed on the google server.. Websites using SSL2 and users can be victimzed in a more silent way by focing weak encryption... That is a security issue with the company not the end user.

  • Never tried this with ettercap. I've used arpspoof for my local network, with tcpdump / and ssl strip.

    Will give it a crack now.

  • ETTERCAP 4TW ! and this guy/girl's using backtrack 3.0 Upwards =)

  • I wonder if being on a switched network it works or you must be connected using a hub.

  • Should work on switched networks and hubbed ones afaik

  • @xplagu3 Will it work on computers on the same switch?

    It shouldnt matter if its running a in a VM?

  • no :) to say in an easy way.... ettercap says hello iam a switch and the whole traffic is reachable!!! nice prog :)

  • @dfrojas The whole point of arp cache poisioning with switches is to get the packets from the other host that a switch normally prevents you from seeing. Hubs will broadcast to all the data to all the ports all the time, and a switch will not.

  • crazy how simple this is...kind of scary in fact

  • Hey Why this video is not rated yet?! it great! =] However when I try I mine MITM attack using ettercap, it is not using fake etherecap's ssl, don't know why :/

  • Cheers. For SSL support make sure you set in the etter.conf file both ec_uid and ec_gid to 0 (root) and uncomment the appropriate redir_command_on and redir_command_off for your system. (my distro was shipped with iptables)

    Hope this helps

  • I'd rather use sslstrip, because you have to accept the SSL Certificate on the victims machine. Which makes it look suspect to those who knows wtf's going on. ;o)

  • which distro are you using?

  • I used Slackware for both boxes in this video. With that said I don't recommend Slackware as a security OS (or in general) due to the paranoia of stability and lack of support for proprietary software. Debian or FreeBSD would be my first picks :)

  • thank you for the answer ..:)

Loading...
Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more