All language subtitles for 11. Injecting Javascript Code

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

So far, we saw a number of things 2

2

that we can do once we become the man in the middle. 3

3

So we saw how we can see anything a target computer 4

4

does on the network. 5

5

So we're able to see the websites, the usernames, 6

6

the passwords, the images, 7

7

anything they load on their browser. 8

8

We also saw that since we're the man in the middle, 9

9

we're able to redirect them to other websites. 10

10

So whenever they request a domain, 11

11

we can redirect them to somewhere else 12

12

by doing a DNS spoofing attack. 13

13

Another really cool thing that we can do 14

14

is modify the HTML, modify the pages 15

15

as they load on the target browser. 16

16

Obviously, this is all possible 17

17

because we are the man in the middle, 18

18

because we're able to intercept all this data. 19

19

So we can wait for the HTML code, 20

20

which is the code that's responsible for loading web pages. 21

21

And as it flows through our computer, 22

22

we can insert any piece of code that we want, 23

23

and the browser will execute this code. 24

24

Now, HTML is only responsible for rendering the elements 25

25

that you see on the web page. 26

26

So it's responsible for the buttons, 27

27

for the forms for the text, 28

28

it doesn't really allow us to do much. 29

29

But modern browsers can execute JavaScript code. 30

30

JavaScript is a powerful programming language 31

31

that we can use to do so many things, 32

32

we can actually modify the whole page, 33

33

remove elements or add elements into the page, 34

34

we can replace links and this is actually 35

35

what I did when I modified the HSTS plugin. 36

36

So I added code that will replace the HTTPS with HTTP. 37

37

And I also added code that will replace 38

38

the actual link the actual domain name 39

39

with this spoof domain name with the one with the dot com 40

40

or to whatever you set it to in the script. 41

41

You can even use it to hooke the browser 42

42

to other browser exploitation frameworks, 43

43

which we can use to further exploit the target 44

44

and even gain full control over their computer. 45

45

And we'll see that later on in the course. 46

46

But for now, I'm gonna show you how to inject 47

47

a very simple JavaScript code into the loaded pages. 48

48

And then we'll build up on that in future lectures 49

49

and see how powerful and useful this can be. 50

50

So right here, I have my Cali machine. 51

51

And before I run better cap and show you 52

52

how to inject JavaScript. 53

53

First of all, we need to have some JavaScript code 54

54

to inject into the target browser. 55

55

So I'm gonna open a text editor. 56

56

And I'm gonna write a very, very simple JavaScript code. 57

57

Like I said, we will see how we can use this 58

58

to run more useful codes. 59

59

But for now, we're keeping this simple 60

60

just to see how we can actually run JavaScript code. 61

61

So all I'm gonna do is alert, open a bracket, 62

62

quotation mark and I'm gonna say JavaScript test. 63

63

I'm gonna close the quotation mark 64

64

and close the bracket and add a semicolon. 65

65

So right here, this code, all it's gonna do 66

66

is it's gonna display a warning message 67

67

and alert message saying JavaScript code. 68

68

So since we're gonna try to inject this code into all pages, 69

69

every time we load a webpage, 70

70

we should see a message saying JavaScript test. 71

71

Now I'm gonna save this. 72

72

So I'm gonna go to file, save, 73

73

and I'm gonna put this in my root directory. 74

74

And I'm just gonna call it alert dot js. 75

75

I'm gonna hit enter and that is saved now in my route, 76

76

so if I quit it, we can see we have the file right here. 77

77

So this is the file that contains the code 78

78

that we want to inject into any webpage 79

79

that loads on the target computer. 80

80

The next step is to go to our HSTS hijack plugin. 81

81

So as I showed you before, this was n-user, 82

82

share better cap caplets, HSTS hijack, 83

83

make sure you use the one that I included in the resources, 84

84

not the one that comes built-in with better cap 85

85

because the built-in one will not work as you wanted. 86

86

So in here we have the HSTS hijack dot cap file. 87

87

This is the configuration file for the whole plugin. 88

88

So I'm gonna right click this and open 89

89

it with my text editor. 90

90

And in here, what we wanna modify 91

91

is the payloads right here. 92

92

So as you can see in here, 93

93

it's already injecting a JavaScript file 94

94

called key logger dot js. 95

95

But we also want to inject our own code. 96

96

So I'm gonna add a comma here 97

97

and I'm gonna add star followed by a colon. 98

98

We added this star right here to say that I want to inject 99

99

my script into any page that the target loads. 100

100

If you want to inject your code into specific domains, 101

101

then you can remove the star and just list the domains 102

102

that you want to inject this code in right here. 103

103

But like I said, we wanna inject this into all pages. 104

104

So I'm gonna put this as a star. 105

105

And after the colon, I'm gonna put the location 106

106

of the JavaScript file that I want 107

107

to inject into the browser. 108

108

So if we look back in here, 109

109

this is the file that we just created, 110

110

which is in route in my home, and it's called alert dot js. 111

111

So I'm gonna put in here, 112

112

I'm just gonna say forward slash route, 113

113

followed by alert dot js. 114

114

And that's it, I'm gonna save this Control+S 115

115

and credit Control+Q, and we are ready to go. 116

116

So I'm gonna go to my terminal, 117

117

I'm gonna run better cap using the exact 118

118

same command that we've been using. 119

119

So we're just giving it the interface as ETH zero 120

120

and we're giving it our spoof file 121

121

to automatically run the ARP spoofing attack, 122

122

putting us in the middle of the connection. 123

123

And as you can see, this is working with not errors, 124

124

so everything is perfect. 125

125

What I also wanna do right now is run my HSTS hijack plugin. 126

126

And as you know, all we have to do is just type HS and tab, 127

127

this will auto complete, I'm gonna hit Enter, 128

128

and everything is running with no errors at all. 129

129

So everything is perfect. 130

130

And as you can see in here, 131

131

it's saying that the payloads, 132

132

it's loading the JavaScript payloads are the key loggers. 133

133

This is the default one that the file already 134

134

was loading and the one that we just specified, 135

135

which is in route alert dot js. 136

136

So now anytime our target loads any web page, 137

137

the whatever code we put in the alert dot js 138

138

should be injected in the loaded page, 139

139

and it should get executed. 140

140

The result of that should show us 141

141

a simple message saying test JavaScript. 142

142

So let's go to the target. 143

143

And as usual, a good idea is just to remove 144

144

the browsing data just to make sure that nothing is cached. 145

145

And I always like to first test with the simplest case, 146

146

and then move on to more complex scenarios. 147

147

So first of all, I'm gonna test it against 148

148

a normal HTTP page, so that there is nothing 149

149

to bypass, no encryption whatsoever. 150

150

So we're just gonna go to vulnweb.com. 151

151

Perfect as you can see, we have an alert message 152

152

in here telling us JavaScript test. 153

153

So basically, this means the JavaScript code 154

154

in my alert dot js file got injected into this page. 155

155

So now that we've verified 156

156

it works against normal HTTP pages, 157

157

let's go ahead and test it against a page that uses HTTPS, 158

158

such as stack overflow.com. 159

159

Perfect, it's working as expected. 160

160

Another example would be linkedin.com. 161

161

Keep in mind, these websites use HTTPS. 162

162

And as you can see, we're able to load them with no HTTPS 163

163

in here, so over HTTP only. 164

164

So even if you log in right here, 165

165

you'll be able to get the username 166

166

and the password as shown before. 167

167

Finally, let's go and test it against the HSTS website 168

168

using the partial HSTS bypass method that I showed you. 169

169

So for that work we'll need to go to Google first of all, 170

170

and we need to go to a Google domain that does not use HSTS. 171

171

Similar to google.ie. 172

172

This is actually the local Google website for Ireland. 173

173

And as you can see, the code works. 174

174

This is fine Google only users HTTPS anyway. 175

175

But let's look for Facebook. 176

176

Now we know Facebook uses HSTS. 177

177

And because HSTS is used, we should not be able 178

178

to inject anything on the website 179

179

because the browser will only load it over HTTPS. 180

180

But using our partial bypass method, 181

181

if I click on Facebook from here, 182

182

as you can see, the code gets executed, 183

183

because what we're loading right now 184

184

is facebook.con, not facebook.com. 185

185

And as you can see, we get a normal Facebook page again, 186

186

that looks identical, and if you log in, 187

187

you'll be able to get the username and the password. 188

188

So as you can see, this work against HTTP 189

189

and HTTPS pages, and even HSTS if the target searches 190

190

for that website, not if they put the domain name in here. 191

191

So if the target comes in and literally types 192

192

facebook.com manually and hit enter, 193

193

the browser will force the HTTPS connection 194

194

as you can see in here, because like I said, 195

195

it has a preloaded list of websites 196

196

that it can only load over HTTPS. 197

197

And because the browser is establishing a HTTPS connection, 198

198

the data will be encrypted 199

199

and therefore we won't be able to inject anything in it.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.