Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Now from the previous lectures we know once we connect to our network it's game over.
Because once connected we can run an AARP spoofing attack to redirect the flow of packets so that they
go through our computer.
This allow us to become the man in the middle.
And once were the man in the middle.
We can run so many dangerous and effective attacks so we can spy on all the users steal their passwords
redirect them to different Web sites.
And this is all just a small taste of what you can do.
You'll actually see us build on this in the client side the tax section where we're going to completely
hack into computers connected to the same network as us.
And if you go and do my advanced network hacking course then you'll see more advanced attacks that will
allow us to do so many cool stuff on the network.
And again all of this is possible because once we connect we can run ERP spoofing and become the man
in the middle now in this section.
I actually want to show you another method that'll allow us to become the man in the middle and once
were the man in the middle.
We'll be able to run all of the attacks that you've seen so far and all of the other man in the middle
attacks that you'll learn in the future so let us go back to the first diagram that we learned in this
course when we were talking about how networks work in general.
We said the only device that has access to the Internet is the access point and whenever a client wants
to access something they send their request to the access point the access point goes through the Internet
gets the response and send it back to the client now.
What if we replace this Access Point with our hacker computer.
So what if we can use our machine to create a Wi-Fi network that actually has internet access so people
will actually try to come in and connect to our network to access the Internet.
And then when they connect to our network by default we will be the man in the middle because we are
the router so we won't really need to exploit anything we are automatically the man in the middle and
the clients will automatically send us any requests because they want to access the Internet and we
will see these requests obviously go to the Internet get them what they want and give it back to them.
This way we'll be able to launch all of the attacks that I showed you previously without the need to
exploit the AARP protocol.
So with that the need to run a R.P. spoofing all will have to do once our network is running and we
have clients connected.
We can just start sniffing using wire shark or using man in the middle F so for this to work you need
a computer and we already have our hacker computer with Kalil Unix.
You also need internet access and you need a wireless device that's going to broadcast the Wi-Fi signal
until all the neighboring devices that I am a network you can come in and connect to me.
So you will need first of all an interface that has Internet connection.
This interface it can be a Wi-Fi interface connected to the Internet.
It could be an either net interface connected to an Ethernet network.
It could be a 3G or a 4G dongle and it even can be a virtual interface.
And this is where I'm actually going to do.
It's going to be my 88 0.
The virtual interface that is connected to my not network so this can be any network device as long
as it has Internet access the next interface that you will need.
Like I said it's going to have to be a Wi-Fi interface because it needs to be able to broadcast the
signal for the network and you can't use any Wi-Fi interface.
This interface needs to be able to act as an access point so it needs to be capable of acting like a
proper access point like character.
Now all of the Wi-Fi adapters that I recommend support this mode and I've already included a video in
the resources before when when I first spoke about wireless adapters but I'm also going to include this
video in the resources of this lecture.
So if you're going to buy one or if you're not sure how to pick the right one then check out this video.
It should be helpful for you.
So once we have this setup properly we can use our computer to start an access point and it's going
to act exactly like her after.
So people will be able to see the network when they look for Wi-Fi networks.
They'll be able to connect to it and get internet connection but when they connect they will have to
send us all of their requests because we are the router we are the access point.
So by default we will be the man in the middle.
Therefore you'll be able to execute all mine in the middle attacks that you learned so far and any other
man in the middle attacks that you will learn in the future so basically AARP spoofing is one method
of becoming the man in the middle.
And well I'm going to show you right now is another method of becoming the man in the middle.
Now you can see that in order to use our computer as an access point we need a number of components
to be configured properly.
So first of all we need our wireless interface to broadcast the signal as if it's a real network.
This will allow other clients to connect to it but that's not the end of the road.
The wireless interface needs to know when these clients are requesting Web sites.
It needs to be able to forward these requests to the other interface that is connected to the Internet.
Then again it will need to be able to know when the responses come back and forward.
All of this to the right client.
Now you can configure all of these things manually and I actually cover this in my advanced network
back in course and I cover a lot of advanced things that you can do with the fake access point like
launch in an evil to an attack.
Hacking into WPA to enterprise and so on.
But this would take at least 30 lectures and this is not a network hacking course.
This is a general ethical hacking course.
Therefore that would be out of the scope of this lecture.
If you're interested in learning how to do this manually and how to do run advanced attacks using the
fake access point then check out my advanced network hacking course in the bonus lecture.
The last lecture of this course for now for this course I'm going to show you a great way of quickly
creating a fake access point that will allow us to become the man in the middle.
Similar to what's shown in this diagram the tool that we're going to use is called minor toolkit and
it's basically a set of tools that allow us to automatically create a fake access point automatically
sniff data bypass hasty G.P.S. and so one so the tool comes with three main starts scripts.
So the first one start no upstream will allow us to start the fake access point with no internet access.
So this is not really useful for us.
And I will not use this in this lecture the next one is third not simple.
This will start a fake access point with Internet access.
The third one start not full will start a fake access point with Internet access it will automatically
start sniffing data and bypass TTP as now way actually always you start not simple.
I never use third not full because this feels a lot of the times and we already learned how to start
sniffing and bypass hash TTP as using better cup so you can always start not simple this or start a
fake access point for you with Internet access and then you can open another terminal window use Buttercup.
Exactly.
As I showed you before and you'll be able to sniff data and bypass TTP yes you can also use wire shark
if you want to sniff the data and analyze them again.
Exactly as shown before.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.