Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Previously we learned what AARP spoofing is and how to use it to intercept connections and our network
using a tool called AARP spoof.
I covered this tool because it is simple reliable and available for a number of operating systems.
Therefore learning how to use this tool can be useful in so many scenarios.
However and this lecture and and the next lectures we're going to be using a tool called better cap
Buttercup can be used to do exactly what we did with AARP spoof so we can use it to run an AARP spoofing
attack to intercept connections and it can be used to do so much more so we can use it to capture data
and analyze it and see usernames and passwords we can use it to bypass hash TTP s and potentially bypass
H S T S we can use it to do DNS spoofing inject code into loaded pages and so much more.
For now though I'm gonna show you how to install the tool and give you a quick overview on how to use
it and we'll go over all of that and the next lectures so I'm gonna go to my Kelly machine here and
to run Buttercup all I have to do now is just type its name Buttercup.
Now as usual if you want to get more information on this command and how to use it you can do dash dash
help.
And this will give you complete help menu but you don't really need to worry about this now because
we will be using the tool a lot throughout the course and you will learn a lot as you use it.
So I'm going to clear the screen again and to run the tool now.
I'm going to type better cap the name of the tool followed by Dash a face to specify the interface that
is connected to the network that I want to run the attacks against.
And as you know to get my interface we can just do if config and I'm gonna be running this against my
not network which is 88 0 is connected to.
So I'm gonna set my interface to 88 0.
I'm going to close this and I'm going to hit enter to run the tool and as you can see now we're inside
the tool.
We have a different prompt now in which we can use the commands of Buttercup now as you can see here.
It's telling us that we can type help to get a list of all of the commands that we can use with better
Cup and since we don't know how to use it I'm actually going to type help on perfect as you can see
we get a full list of all of the commands that we can use.
Again we're going to use it with you now as we go through the course.
So he can have a quick look on them but don't worry too much about them.
What's really important and you need to pay attention to right now is the modules.
So these are all of the modules that we can use or all of the things that we can get better cab to do.
And as you can see right now none of them is working except for the events stream which is basically
the module that runs in the background to handle all the events.
Now you can type help followed by the name of any module you want.
And this will show you a help menu that shows you how to use this specific module.
For example I want to show you in this lecture the net dot probe and the net dot recon modules.
So since I don't know how to use them I've typed help and I'm going to follow it by the name of the
module which is net dot pro I'm going to hit enter and as you can see you'll get a description of what
this module does.
So basically it keeps sending UDP packets to discover devices on the same network and we can do a net
probe on to turn on the module and net that probe off to turn it off.
You can also see all the options that you can modify for this module.
And I'm going to talk about options and how to modify them in the next lecture.
So for now I'm going to keep all these two the default option and I'm just going to do net dot probe
on to turn it on.
And as you can see this will automatically start discovering clients connected to the same network.
So the 10 0 2 7 right here is actually my windows target machine.
So if I go to the target Windows machine right here and do IP config you'll see its I.P. address is
10 0 2 7.
So this is just another way of discovering connected clients quickly using better cup.
And what you didn't notice right now is when we started the net dot pro it automatically started the
net dot recon to confirm this.
So if we go up right here you can see the only module that was running is the events dot stream.
And now if I do help you'll see I actually have two modules running the net dot probe which we just
so and we turned on manually.
And the net dot three con which got turned on automatically by better cap.
The reason for this is because the net dot probe sends probe requests to all possible eyepiece.
And then if we get a response the net the three con will be the one detecting this response by monitoring
my AARP cache and then adding all of these IP is in a nice list so we can target them so now because
the net the three corners is actually running we can do net the show to see all of the connected clients.
And as you can see we get a nice list of all of the connected clients we can see their IP is we can
see the corresponding mac addresses for these clients and it can also show you information right here
about each one of these APIs.
For example it's telling us that this IP right here is the IP for 88 0.
So this is the IP of this computer it's also telling us that this IP right here is the gateway.
This is the IP of the router and you can also see at the vendor in here it's attempting to discover
the manufacturer of the hardware used in each of these clients.
So as you can see for the Gateway it thinks that it uses a real tech chipset.
Now you can also see here the standard 0 0 2 7 device.
Like I said this is my target.
Windows device right here.
So that's it for this lecture.
I just wanted to give you a quick overview on how to get help about a specific module how to run a specific
module and analyze the results that it returns.
And in the next lecture I'm going to show you how we can run and ERP spoofing attack using Buttercup
to intercept the data and read usernames and passwords that flow through the network once we become
the man in the middle.
Once we intercept the connection.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.