+ All Categories
Home > Documents > Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0...

Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0...

Date post: 12-Aug-2020
Category:
Upload: others
View: 3 times
Download: 0 times
Share this document with a friend
12
Hijacking Web 2.0 Sites with SSLstrip Hands-on Training
Transcript
Page 1: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Hijacking Web 2.0

Sites with SSLstrip

Hands-on Training

Page 2: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Contact

Sam Bowne

Computer Networking and Information

Technology

City College San Francisco

Email: [email protected]

Web: samsclass.info

Page 3: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

The Problem

HTTP Page with an HTTPS Logon Button

Page 4: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Proxy Changes HTTPS to

HTTP

Target

Using

Facebook

Attacker:

Evil Proxy

in the

Middle

To

Internet

HTTP

HTTPS

Page 5: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Ways to Get in the

Middle

Page 6: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Physical Insertion in a Wired

Network

Target

Attacker

To

Internet

Page 7: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Configuring Proxy Server in

the Browser

Page 8: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

ARP Poisoning

Redirects Traffic at Layer 2

Sends a lot of false ARP packets on the

LAN

Can be easily detected

DeCaffienateID by IronGeek

http://k78.sl.pt

Page 9: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

ARP Request and Reply

Client wants to find Gateway

ARP Request: Who has 192.168.2.1?

ARP Reply:

MAC: 00-30-bd-02-ed-7b has 192.168.2.1

Client Gateway Facebook.com

ARP Request

ARP Reply

Page 10: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

ARP Poisoning

Client Gateway Facebook.com

Attacker

ARP Replies: I

am the

Gateway

Traffic to

Facebook

Forwarded &

Altered Traffic

Page 11: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Demonstration

Page 12: Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training CON 17/DEF CON 17... · Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training Author: Sam Bowne Subject: Hijacking Web

Do it Yourself

You need a laptop with

Windows host OS

VMware Player or Workstation

Linux Virtual Machine (available on the USB

Hard Drives in the room)

Follow the Handout


Recommended