Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
In the previous lectures, 2
2
we learned how to use Bettercap 3
3
to discover all clients on the same network, 4
4
run an ARP spoofing attack to intercept the data 5
5
and then sniff data to see the usernames, passwords, 6
6
and everything that's getting sent over the network. 7
7
Now in order to do this, 8
8
we actually had to run a number of commands. 9
9
So first of all, we had to do net.probe on, 10
10
to turn on the probe module. 11
11
We had to set the settings for the ARPspoof module, 12
12
turn that on, and then turn the sniffing module on. 13
13
Now, every time you want to do this, 14
14
every time you want to intercept data and see it onscreen, 15
15
you're gonna have to do all of the steps that I showed you 16
16
in the previous lecture. 17
17
Or if you're lazy like myself, 18
18
you can use a caplet to do all of that automatically, 19
19
which is exactly what I wanna show you in this lecture. 20
20
So what do I mean by a caplet? 21
21
Well, basically a caplet is just a text file 22
22
that contains all of the commands that you want to run. 23
23
So I'm gonna resize this menu. 24
24
I'm gonna open a text file 25
25
and I'm just gonna organize this a little bit 26
26
to make it easier to follow 27
27
and I'm gonna clear this window here 28
28
and I'm gonna go to the first command that we had to run 29
29
in order to do this. 30
30
So again scrolling up, the first thing we did 31
31
was net.probe on. 32
32
So in my text file here, 33
33
I'm gonna literally type this command, net.probe on. 34
34
And as we saw, this will automatically start 35
35
the net.recon module. 36
36
Again, we enabled both of these modules 37
37
in order to discover the connected clients 38
38
and keep automatically discovering any new clients 39
39
that connect to the network. 40
40
The next thing that we did 41
41
was modify the settings for the ARPspoof module. 42
42
So we did set ARPspoof full duplex to true. 43
43
I'm gonna actually copy this and paste it here. 44
44
Then we set the target IP. 45
45
So again, I'm just gonna copy this and paste it here 46
46
and keep in mind this is very important. 47
47
You wanna make sure that you change the IP here 48
48
to the IP of your target all the time. 49
49
And if you are targeting multiple computers, 50
50
you can just use the comma 51
51
and type the next IP after the coma. 52
52
Next we turned on the ARPspoof module. 53
53
So again, this is what I'm gonna do here. 54
54
I'm gonna do arp.spoof on. 55
55
And finally we also run the sniffer by doing net.sniff on. 56
56
So again, I'm just gonna type this in here, net.sniff on. 57
57
So this is actually a nice summary 58
58
of what we did in the previous lectures. 59
59
Again, like I said, 60
60
every time you wanna intercept the connections, 61
61
you're gonna have to start Bettercap 62
62
and run all of these commands manually. 63
63
You wanna start the probe module, 64
64
you wanna enable the full duplex. 65
65
So you full or spoof the target and the router. 66
66
You wanna set your target IP 67
67
and you wanna turn on the spoof and turn on the sniff. 68
68
So to make this very easy, 69
69
instead of having to type this every time 70
70
we want to run an ARP spoofing attack and intercept data, 71
71
I put all of this in a text file. 72
72
I'm gonna save this text file. 73
73
I'm gonna put it in my root directory 74
74
and I'm gonna call it spoof.cap. 75
75
So I'm gonna save this now and I can close it 76
76
because we're done with it and we can go back here. 77
77
And what I'm actually gonna do, I'm gonna exit out of this. 78
78
So I'm gonna quit Bettercap and I'm gonna clear the screen. 79
79
And if I do LS to list all of the files and directories 80
80
in the current working directory, 81
81
because right now I am in root. 82
82
So if I do LS, you can see we have a new file 83
83
called spoof.cap. 84
84
And just to confirm, 85
85
if I go down to my file manager right here, 86
86
you can see we have a new file, again in the root 87
87
called spoof.cap. 88
88
And all we want to do, is feed this spoof file 89
89
to Bettercap before we start Bettercap. 90
90
Now, we don't know how to do this, 91
91
so we're gonna do bettercap--help to see all of the options 92
92
that we can set with Bettercap. 93
93
And what we want to do is use the -caplet option right here. 94
94
So we're gonna run Bettercap like we used to do. 95
95
First of all, we do Bettercap followed by iface 96
96
to specify the interface that is connected 97
97
to the target network and in my case this is ETH0. 98
98
So, so far this is identical 99
99
to what I've been doing in the previous lectures. 100
100
The only difference now, 101
101
is we're gonna use the -caplet option 102
102
to specify my caplet file that I just created. 103
103
So I'm gonna do -caplet 104
104
followed by the file that I just created, 105
105
which is called spoof.cap and that's it. 106
106
Now, before I hit enter, just to confirm to you, 107
107
I'm gonna go back to my windows machine 108
108
and I'm gonna do ARP-a to show you. 109
109
And as you can see right now, 110
110
the router's IP right here, has this MAC address. 111
111
So after I run this, 112
112
it should automatically start all of the modules 113
113
that I just typed and it should run an ARP spoofing attack. 114
114
Therefore, the router's MAC address 115
115
should change to the MAC address of ETH0 116
116
that is connected to kali right here. 117
117
So I'm gonna hit enter and as you can see, 118
118
we actually got an error 119
119
and the error is saying the caplet spoof could not be found. 120
120
So I'm suspecting I made a spelling mistake and I did. 121
121
As you can see, I actually named the caplet soof not spoof. 122
122
So I actually make a lot of mistakes like this. 123
123
So I'm just gonna rename this to spoof 124
124
and we're gonna go back here. 125
125
I'm gonna exit and run the same command again, and perfect. 126
126
As you can see, we got no errors at all. 127
127
If I do help, as you can see 128
128
automatically we have this spoof is running. 129
129
We have the probe, the recon, and the sniff all running 130
130
as soon as we run Bettercap. 131
131
If you remember the first time we ran it, 132
132
we only had the stream running 133
133
and we had to do everything manually 134
134
and set the options manually. 135
135
So this is a really, really nice way of doing it. 136
136
Now let's confirm that everything is working as expected. 137
137
So I'm gonna go to the windows machine 138
138
and we're gonna do ARP-a again. 139
139
And perfect, as you can see, the routers MAC address 140
140
has changed to the same MAC address as the kali machine 141
141
and the original routers MAC address, 142
142
the correct one was this. 143
143
So this means that this windows machine 144
144
is now spoofed, thinking that the kali machine is the router 145
145
and the router now thinks 146
146
that the kali machine is this machine. 147
147
This will place kali in the middle of the connection. 148
148
And just to confirm this, just real quick, 149
149
I'm already in vulnweb. 150
150
This is the website that we tested the login before. 151
151
I'm actually even still logged in. 152
152
So I'm gonna log out, log in again, 153
153
and I'm gonna leave the username to admin 154
154
and I'm just gonna put a password again, 155
155
one, two, three, four to nine zero, enter. 156
156
Let's go back and perfect. 157
157
As you can see, we wouldn't be able to get this 158
158
if we were not in the middle of the connection. 159
159
So the fact that we're getting all of this information 160
160
means that we managed to intercept the data 161
161
and see everything the target user sends or receives. 162
162
And again we have the username and the password right here. 163
163
Like I said, this will only work with HTTP. 164
164
We will discuss HTTPS in the next lectures. 165
165
But in this lecture I just wanted to show you an easy way 166
166
of scripting the commands that you often run with Bettercap 167
167
because in the future 168
168
we're gonna be doing a number of things 169
169
that rely on us being the man in the middle. 170
170
So because I don't want to waste time 171
171
enabling all of the modules that we're running here. 172
172
So again, if I right click this 173
173
and open with a normal text editor, 174
174
all you'll have to do is just put your commands in a file, 175
175
give a file a specific name, 176
176
and then when you're on Bettercap, all you have to do 177
177
is just use the caplet argument, 178
178
followed by the name of your caplet file.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.