Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Does SSLSTRIP still work? filter_list
Author
Message
Does SSLSTRIP still work? #1
If I would've walked into Starbucks, and fired up SSLSTRIP, would I still be able to sniff on an IP on the network? Unless they have a VPN..

If SSLSTRIP works, then I guess Evil Twin works...

Donate?
Bitcoin: 1NHEhkSoChFuMt9H9yk3HXyLepqG2sEjJ8

Reply

RE: Does SSLSTRIP still work? #2
Not entirely sure if it still works, to be honest.
[Image: fSEZXPs.png]

Reply

RE: Does SSLSTRIP still work? #3
Alright, just did some more research onto the topic, it seems to work on all sites except Gmail and Twitter because they use HSTS headers, which GOOGLE and FIREFOX supports, which makes it not vulnerable anymore for those sites, however, if the user uses Safari, it would work.

SOURCE:
https://www.owasp.org/index.php/HTTP_Str...t_Security
And...
https://forums.hak5.org/index.php?/topic...l-twitter/

Donate?
Bitcoin: 1NHEhkSoChFuMt9H9yk3HXyLepqG2sEjJ8

Reply

RE: Does SSLSTRIP still work? #4
I don't think so, we've got sslstrip2 and dns2proxy.py and the brrowser you mentioned are vulnerably ("Firefox && Chrome")
[Image: oAnNAVY.png]

Reply

RE: Does SSLSTRIP still work? #5
Nowdays, doesn't work sslstrip so HSTS but you can use MITMF for break this.
https://github.com/byt3bl33d3r/MITMf
http://i.imgur.com/nmBhLHB.png

Reply

RE: Does SSLSTRIP still work? #6
Hy
Googling fot hsts hack i found you guys.
Dos anyone have this program for hsts? I saw it on yt:
https://www.youtube.com/watch?v=m-o-UPBLqvU

Thanks

Reply







Users browsing this thread: 4 Guest(s)