Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
So far, we saw a number of things 2
2
that we can do once we become the man in the middle. 3
3
So we saw how we can see anything a target computer 4
4
does on the network. 5
5
So we're able to see the websites, the usernames, 6
6
the passwords, the images, 7
7
anything they load on their browser. 8
8
We also saw that since we're the man in the middle, 9
9
we're able to redirect them to other websites. 10
10
So whenever they request a domain, 11
11
we can redirect them to somewhere else 12
12
by doing a DNS spoofing attack. 13
13
Another really cool thing that we can do 14
14
is modify the HTML, modify the pages 15
15
as they load on the target browser. 16
16
Obviously, this is all possible 17
17
because we are the man in the middle, 18
18
because we're able to intercept all this data. 19
19
So we can wait for the HTML code, 20
20
which is the code that's responsible for loading web pages. 21
21
And as it flows through our computer, 22
22
we can insert any piece of code that we want, 23
23
and the browser will execute this code. 24
24
Now, HTML is only responsible for rendering the elements 25
25
that you see on the web page. 26
26
So it's responsible for the buttons, 27
27
for the forms for the text, 28
28
it doesn't really allow us to do much. 29
29
But modern browsers can execute JavaScript code. 30
30
JavaScript is a powerful programming language 31
31
that we can use to do so many things, 32
32
we can actually modify the whole page, 33
33
remove elements or add elements into the page, 34
34
we can replace links and this is actually 35
35
what I did when I modified the HSTS plugin. 36
36
So I added code that will replace the HTTPS with HTTP. 37
37
And I also added code that will replace 38
38
the actual link the actual domain name 39
39
with this spoof domain name with the one with the dot com 40
40
or to whatever you set it to in the script. 41
41
You can even use it to hooke the browser 42
42
to other browser exploitation frameworks, 43
43
which we can use to further exploit the target 44
44
and even gain full control over their computer. 45
45
And we'll see that later on in the course. 46
46
But for now, I'm gonna show you how to inject 47
47
a very simple JavaScript code into the loaded pages. 48
48
And then we'll build up on that in future lectures 49
49
and see how powerful and useful this can be. 50
50
So right here, I have my Cali machine. 51
51
And before I run better cap and show you 52
52
how to inject JavaScript. 53
53
First of all, we need to have some JavaScript code 54
54
to inject into the target browser. 55
55
So I'm gonna open a text editor. 56
56
And I'm gonna write a very, very simple JavaScript code. 57
57
Like I said, we will see how we can use this 58
58
to run more useful codes. 59
59
But for now, we're keeping this simple 60
60
just to see how we can actually run JavaScript code. 61
61
So all I'm gonna do is alert, open a bracket, 62
62
quotation mark and I'm gonna say JavaScript test. 63
63
I'm gonna close the quotation mark 64
64
and close the bracket and add a semicolon. 65
65
So right here, this code, all it's gonna do 66
66
is it's gonna display a warning message 67
67
and alert message saying JavaScript code. 68
68
So since we're gonna try to inject this code into all pages, 69
69
every time we load a webpage, 70
70
we should see a message saying JavaScript test. 71
71
Now I'm gonna save this. 72
72
So I'm gonna go to file, save, 73
73
and I'm gonna put this in my root directory. 74
74
And I'm just gonna call it alert dot js. 75
75
I'm gonna hit enter and that is saved now in my route, 76
76
so if I quit it, we can see we have the file right here. 77
77
So this is the file that contains the code 78
78
that we want to inject into any webpage 79
79
that loads on the target computer. 80
80
The next step is to go to our HSTS hijack plugin. 81
81
So as I showed you before, this was n-user, 82
82
share better cap caplets, HSTS hijack, 83
83
make sure you use the one that I included in the resources, 84
84
not the one that comes built-in with better cap 85
85
because the built-in one will not work as you wanted. 86
86
So in here we have the HSTS hijack dot cap file. 87
87
This is the configuration file for the whole plugin. 88
88
So I'm gonna right click this and open 89
89
it with my text editor. 90
90
And in here, what we wanna modify 91
91
is the payloads right here. 92
92
So as you can see in here, 93
93
it's already injecting a JavaScript file 94
94
called key logger dot js. 95
95
But we also want to inject our own code. 96
96
So I'm gonna add a comma here 97
97
and I'm gonna add star followed by a colon. 98
98
We added this star right here to say that I want to inject 99
99
my script into any page that the target loads. 100
100
If you want to inject your code into specific domains, 101
101
then you can remove the star and just list the domains 102
102
that you want to inject this code in right here. 103
103
But like I said, we wanna inject this into all pages. 104
104
So I'm gonna put this as a star. 105
105
And after the colon, I'm gonna put the location 106
106
of the JavaScript file that I want 107
107
to inject into the browser. 108
108
So if we look back in here, 109
109
this is the file that we just created, 110
110
which is in route in my home, and it's called alert dot js. 111
111
So I'm gonna put in here, 112
112
I'm just gonna say forward slash route, 113
113
followed by alert dot js. 114
114
And that's it, I'm gonna save this Control+S 115
115
and credit Control+Q, and we are ready to go. 116
116
So I'm gonna go to my terminal, 117
117
I'm gonna run better cap using the exact 118
118
same command that we've been using. 119
119
So we're just giving it the interface as ETH zero 120
120
and we're giving it our spoof file 121
121
to automatically run the ARP spoofing attack, 122
122
putting us in the middle of the connection. 123
123
And as you can see, this is working with not errors, 124
124
so everything is perfect. 125
125
What I also wanna do right now is run my HSTS hijack plugin. 126
126
And as you know, all we have to do is just type HS and tab, 127
127
this will auto complete, I'm gonna hit Enter, 128
128
and everything is running with no errors at all. 129
129
So everything is perfect. 130
130
And as you can see in here, 131
131
it's saying that the payloads, 132
132
it's loading the JavaScript payloads are the key loggers. 133
133
This is the default one that the file already 134
134
was loading and the one that we just specified, 135
135
which is in route alert dot js. 136
136
So now anytime our target loads any web page, 137
137
the whatever code we put in the alert dot js 138
138
should be injected in the loaded page, 139
139
and it should get executed. 140
140
The result of that should show us 141
141
a simple message saying test JavaScript. 142
142
So let's go to the target. 143
143
And as usual, a good idea is just to remove 144
144
the browsing data just to make sure that nothing is cached. 145
145
And I always like to first test with the simplest case, 146
146
and then move on to more complex scenarios. 147
147
So first of all, I'm gonna test it against 148
148
a normal HTTP page, so that there is nothing 149
149
to bypass, no encryption whatsoever. 150
150
So we're just gonna go to vulnweb.com. 151
151
Perfect as you can see, we have an alert message 152
152
in here telling us JavaScript test. 153
153
So basically, this means the JavaScript code 154
154
in my alert dot js file got injected into this page. 155
155
So now that we've verified 156
156
it works against normal HTTP pages, 157
157
let's go ahead and test it against a page that uses HTTPS, 158
158
such as stack overflow.com. 159
159
Perfect, it's working as expected. 160
160
Another example would be linkedin.com. 161
161
Keep in mind, these websites use HTTPS. 162
162
And as you can see, we're able to load them with no HTTPS 163
163
in here, so over HTTP only. 164
164
So even if you log in right here, 165
165
you'll be able to get the username 166
166
and the password as shown before. 167
167
Finally, let's go and test it against the HSTS website 168
168
using the partial HSTS bypass method that I showed you. 169
169
So for that work we'll need to go to Google first of all, 170
170
and we need to go to a Google domain that does not use HSTS. 171
171
Similar to google.ie. 172
172
This is actually the local Google website for Ireland. 173
173
And as you can see, the code works. 174
174
This is fine Google only users HTTPS anyway. 175
175
But let's look for Facebook. 176
176
Now we know Facebook uses HSTS. 177
177
And because HSTS is used, we should not be able 178
178
to inject anything on the website 179
179
because the browser will only load it over HTTPS. 180
180
But using our partial bypass method, 181
181
if I click on Facebook from here, 182
182
as you can see, the code gets executed, 183
183
because what we're loading right now 184
184
is facebook.con, not facebook.com. 185
185
And as you can see, we get a normal Facebook page again, 186
186
that looks identical, and if you log in, 187
187
you'll be able to get the username and the password. 188
188
So as you can see, this work against HTTP 189
189
and HTTPS pages, and even HSTS if the target searches 190
190
for that website, not if they put the domain name in here. 191
191
So if the target comes in and literally types 192
192
facebook.com manually and hit enter, 193
193
the browser will force the HTTPS connection 194
194
as you can see in here, because like I said, 195
195
it has a preloaded list of websites 196
196
that it can only load over HTTPS. 197
197
And because the browser is establishing a HTTPS connection, 198
198
the data will be encrypted 199
199
and therefore we won't be able to inject anything in it.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.