Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Backtrack Series - 12: Session Hijacking for Secure Websites

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
28,053
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 6, 2009

In this tutorial we will hijack a live session so that we can have the same priviliges of the account without having any information about the username and password. We will start by redirecting the secure traffic to an insecure server using SSLStrip, next we use ferret to extract cookies from the traffic and then we will use hamster to inject the cookies in the browser

For more information, please check:

  • likes, 1 dislikes

Link to this comment:

Share to:

Uploader Comments (fifothekid)

  • could you upload it again i mean roguev3.sh link is dead on remote forum :(

    rapishare will do good

  • @illegalmexicain try this link:

    w w w . m u l t i u p l o a d . c o m / J 1 9 D Q X C F E 7

    Don't forget to remove the spaces

  • this video let me access my networks computer??whats the profit please reply!!

  • @rabih212 you really didn't understand the goal of this video...

  • Thnx for your reply

    1- I didn't try wifizoo before. But the aim of my tutorials is to provide more than one approach for the same problem, as some people told me that wifizoo didn't work for them

    2- grep for what? Cookie hijacking is not about getting the username and password. It's rather about fooling the server into thinking that you are the one who logged to the server, without even providing any username and password.

see all

All Comments (11)

Sign In or Sign Up now to post a comment!
  • subscribing now!!

  • @fifothekid thanks alot, i think you were my only hope to get this file i uploaded the file to multiupload and share with other people i did put a legal notice in it just in case ;)

  • Why ferret and hamster? I thought wifizoo was able to do both of this (I'm probably wrong :P)

    Also I normally log everything I capture to a file and then grep what I want. I don't see any advantages to using cookies, care to explain please? Very good video!

  • is the rouge ap step necessary? or is it just to show a way of getting on the same network as the victim?

    also i noticed you have ettercap running, your just using that with sslstrip right?

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more