Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Hak5: Man in the Middle Hacking Fun with SSL Strip

Loading...

Sign in or sign up now!
35,348
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Oct 20, 2009

This time on the show Darren's having a little man-in-the-middle fun with a demonstration os SSLStrip, an epic tool for removing that pesky encryption from your victims browsing session. Plus Laser Cat Modding

Moxie Marlinspike's SSLStrip, released at Blackhat/DEFCON this year, is a tool that transparently hijacks HTTP traffic and redirects HTTPS links to look-alike HTTP links. While this description barely scratches the surface, Darren's segment takes a closer look including a pracitcal demonstration of a man-in-the-middle attack using arpspoof and a little luck with remote-exploit's BackTrack 4 penetration testing distribution.

  • likes, 4 dislikes

Link to this comment:

Share to:

Uploader Comments (Hak5Darren)

  • soco + packets = score

  • mmmmmm packets

  • LOL DArren your SExy and you crack me up - OOP

  • damn skippy

  • Win, I just learned a new word for less than/greater than.. Wakka.. :)

  • wakka wakka wakka wakka *power pellet sound*

Top Comments

  • Darren is a pretty cool guy. He has drinks in his hair and doesn't afraid of anything.

Video Responses

see all

All Comments (75)

Sign In or Sign Up now to post a comment!
  • 11:23 Haha what?

  • Whenever I am arp spoofing it kills my internet on the target machine. (Not sure about other machines) How do I fix this.

  • Can anyone please tell if Ettercap is a legit (=safe) tool for pentesting? Would it be possible to cause any harm with it beyond your knowledge, like spreading viruses or worms in a otherwise "clean" environment?

    In other words, is it itself a safe/clean application to use professionally?

    I am referring to normal usage, without implementing any harmful code myself, where it only works as a sniffer.

  • best hack tools at SOFTWAREFORYOU(dot)TK

  • @theoriginalfatdonkey fuck you i love it when they talkz

    

  • 0:00

  • @acdcgreatestbandever Well it's not really a downside. It isn't that hard the connect to protected wifi, because you can crack WPA and WEP passwords. Also a Man-in-the-Middle attacks would be smarter by manually sniffing out the info rather than a Trojan, because most people are smart enough to have an antivirus, so it would be detected easily.

  • i couldn't help but notice your shirt.

    i happen to like LDAP! but, you know. openldap's implementation.

  • Holy fuck, SKIP ALL THAT BULLSHIT AT THE START. Like, the first 7 minutes. Thanks.

View all Comments »
Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more