Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
And this lecture we're going to talk about a tool called whale shark why a shark is a network protocol
analyzer.
It's not designed for hackers and it's not designed for hacking and spying on other people on the network.
It's designed for network administrators so that they can see what's happening in their network and
make sure that everything is working properly and that nobody is doing anything bad or doing anything
suspicious on the network the way that whale shark works is it allows you to select an interface and
then logs all the packets or all the traffic that flows through that interface.
So you're selecting an interface it could be a wireless card.
It could be a wired card on your on your current computer and then it'll start logging all the information
that flow through that interface.
It also has a really nice graphical interface that allow you to analyze this traffic.
So it allows you to filter these packets based on the protocol using them like HDTV TGP and all that
but also allow you to look for certain things for example if you're looking for cookies or if you're
looking for post or get requests.
And it also allow you to search through these packets it can you can you can search through the information
that's stored in the packets and find the things that you're looking for.
It's a really really big tool and you need a whole course for it.
So in this course we're actually gonna use it in a few lectures just covering the basics or the things
that's related to us so the main idea here is why shark is not a hacking tool it only allows you to
capture the traffic that flows through your own computer through your own interface I'm going to use
it now and it's going to become more clear to you.
So I'm just gonna go to Carly and we're going to start to our shark.
You can run wild shark from the command prompt or you can just go on all applications and type via shark
and it'll show up right here I'm going to click that and that's going to load the program for me.
This is just the normal error.
Just ignore this error and this is the main interface of where shark.
So first of all you can actually just go to the file and go to the open and in here it'll allow you
to open a file that you've already captured so for example if you captured packets using a different
sniffer use an error dump or use in man in the middle left or using teh shark which is the command prompt
part of the shark.
So if you captured packets using any of these programs and you started it in a file you can just come
in here open it and start analyzing that file.
This is really handy because sometimes you don't really want to analyze the traffic on the fly so sometimes
you just want to capture it if you're sometimes you capture it from small laptop or your small capture
and from your phone and you're not even at home you're in somewhere else doing your pen test and then
you go back home and then you want to analyze what you captured then you can still do that in a file
and then just come here go to the file open and open the file that you want to analyze.
So what I want to show you here is the idea that while shark is not a hacking tool it's not going to
capture things happening in a in another device.
It will only capture things that flow through your own interface.
So right here we can see that we have all the interfaces in my computer so we can see that we have 88
0 we have any which is just any and we have all the other ones that some of them are created by virtual
box.
So the main one here is a zero which is the virtual interface connected to my not network and you can
see that there is no traffic flowing through this so you can see that this is constant and nothing's
happened in.
So what I'm going to do now is I'm just gonna make this a little bit smaller and I'm going to open my
browser here and I'm just gonna go to a normal Web site I'm just gonna go to Google dot com
now as you can see right here you can see the traffic 80 heads euro is a spike in up so there was some
traffic generated through 88 0.
So for sniffing on this we'll be able to capture these packets that were sent over 88 0.
Now what I'm gonna do is I'm gonna go through my windows machine just to prove that point and I'm going
to browse the Web site here and you'll see that 88 0 will not be affected and the traffic that's generated
on this Windows machine which is in the same network as the killing machine it will not be captured
by the Cally machine.
So if I just go to Google again here you'll see that nothing happened in 88 0.
So there is no traffic flowing through this.
It's still constant.
And we can only capture packets that go through 88 0.
So now you'll probably ask then why why are sharks so useful why are we even talking about it.
If we can 3D if we can only see things that go through our own computer why are we talking about it.
Well we're talking about it because we see there is a large number of ways that you can become the man
in the middle.
We learned how to do this using a Sharpie spoofing.
And in future lectures I'm gonna show you how to do it by creating a fake access point so when we are
the man in the middle.
If we start sniffing on the interface that's used to become the man in the middle.
We'll be able to capture all the traffic generated by the people that were targeting in our mind in
the middle attack.
So if you if you started the fake access point you can start sniffing on the interface that's broadcasting
the signal and you can capture all the packets sent or received.
To anyone who's connected to that fake access point if you became the man in the middle using a peaceful
spoofing then just select the interface that you used when you launched your IP spoofing attack.
So for now I'm going to become the man in the middle using AARP spoofing.
You can use AARP spoof or Buttercup as I showed you earlier but I'm going to use Buttercup using the
exact same command that we used to do.
So we're literally just doing Buttercup followed by the interface that is connected to my target network
which is 88 0 and I'm launch in my couplet.
The spoof couplet so that it can figures the AARP spoof module and runs it for me to put me in the middle
of the connection so I'm gonna hit enter.
And as you can see it's working as expected.
So right now I should be in the middle of the connection intercepting anything.
The target Windows machine sends or receives.
Now let's go to the Windows machine and see if I do anything here.
If it's going to affect the traffic in 88 0 so we'll see if Fairchild could be able to capture traffic
generated by this computer.
So let's write anything here.
I'm just going to Google or I'm just gonna go to a different Web site I'm just gonna go to Bing
and if we come back here you'll see that we have traffic being generated here and we can see that 88
zero is actually capturing whatever that's happening in a completely different device.
This is happening because when we are the man in the middle all the packets that's generated by the
Windows device has actually been redirected to my own computer right here to the Kali and then wired
shark is sniffing that from the Kali machine sniffing it from my own local machine it's not sniffing
it from the network is not sniffing it from the target computer.
So again if you're doing this with the fake access point then just listen on the interface that you're
broadcasting if you're doing this with a real wireless network if you're connected to your home wireless
network using land zero then you can just do this with land zero but with a peaceful thing you have
to first redirect the traffic then you can use wire shark.
Now this is just to show you what why a shark is and how it works.
And I just wanted to stress the idea that our shark is not a hacking tool.
It's only a program that allows you to log packets flowing through a certain interface and then analyze
these packets.
So in the next video we'll see how we can sniff and analyze packets using wire shark.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.