All language subtitles for 7. Understanding HTTPS & How to Bypass it

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

Now everything that we did so far 2

2

will only work against HTTP pages. 3

3

The reason why it works against HTTP 4

4

because as we've seen the data and HTTP 5

5

is sent as plain text. 6

6

So it's text that humans like us can read and understand. 7

7

That's why when we are the man in the middle 8

8

we are able to read this text. 9

9

And if we wanted 10

10

we are able to modify this text as we wish. 11

11

Now this is obviously a problem 12

12

and this problem was fixed in HTTPS. 13

13

So as you know most websites use HTTPS 14

14

the reason why, like I said 15

15

because it's a more secure version of HTTP 16

16

and basically the way it works is 17

17

it adds an extra layer over HTTP 18

18

which is where the S comes from. 19

19

So it's a secure HTTP protocol 20

20

and this extra layer will encrypt 21

21

the plain text data that HTTP sends. 22

22

So if a person manages to become the man in the middle 23

23

they will be able to read this data. 24

24

But the data will be gibberish, 25

25

it will not be readable 26

26

to the person intersecting the connection. 27

27

Now HTTPS relies on TLS or SSL 28

28

to encrypt the data., 29

29

and this is every difficult to break. 30

30

Therefore in order to by pass this 31

31

the easiest method is to downgrade 32

32

HTTPS connections to HTTP. 33

33

So since we are the man in the middle 34

34

we can check if the target is requesting a HTTPS website. 35

35

And instead of giving him the HTTPS version of that website 36

36

we will give him the HTTP version. 37

37

This way the data will be sent in plain text, 38

38

and we will be able to read it exactly as I showed you 39

39

in the previous lecture. 40

40

To do this we'll have to manually configure 41

41

and use a tool called SSL Strip. 42

42

And I show how to do this is my more advanced courses. 43

43

But luckily BetterCAP has a caplet 44

44

that will do all of this for us. 45

45

The only problem is this caplet does not replace 46

46

all HTTPS links to HTTP 47

47

in the loaded pages. 48

48

So I modified this caplet for you 49

49

to make sure that it's gonna work as expected. 50

50

And I've included it in the resources of this lecture. 51

51

So all we have to do is download the zip 52

52

in the resources of this lecture 53

53

and I have it downloaded in my Kali machine. 54

54

So I'm gonna go to my files and to my downloads. 55

55

And I have it right here. 56

56

It;s called hstshijacked.zip. 57

57

I'm gonna right click it and extract it here. 58

58

This is the folder of this caplet, 59

59

and I'm gonna copy it 60

60

and paste it in the correct location, 61

61

where BetterCAP loads caplets from. 62

62

So to go to that location, 63

63

you can either press Control and L on your keyboard 64

64

to open the Path Bar, or you can press here 65

65

and press forward slash again to open the Path Bar. 66

66

Once the Path Bar is open 67

67

we wanna go to USR, 68

68

share, 69

69

BetterCAP, caplets. 70

70

So like I said this is the default location 71

71

where BetterCAP stores all of the caplets. 72

72

I'm gonna hit Enter 73

73

and as you can see we already have this caplet in here 74

74

but like I said this caplet is buggy, 75

75

it doesn't work as expected. 76

76

So I'm gonna delete it. 77

77

So right click, move to Trash. 78

78

And I'm gonna paste the one I just copied in here. 79

79

So that's it, we're good to go. 80

80

We can go ahead and use this caplet from BetterCAP. 81

81

But before we do that, 82

82

I also want to go to my home directory, 83

83

this is where I stored the caplet that we created 84

84

in the previous lecture. 85

85

The spoof caplet, 86

86

the one that will run the ARP spoofing command. 87

87

And then run the sniffer. 88

88

I just wanna modify one thing in this. 89

89

So I'm gonna right click it, and open it with Leafpad. 90

90

And what I wanna modify is, 91

91

I want to add an option to the sniff in here. 92

92

So as you know the line net.sniff.on 93

93

will turn on my sniffer, 94

94

but before turning it on, 95

95

I want to set the net.sniff.local to true 96

96

and what this option will do 97

97

it will tell BetterCAP to sniff all data 98

98

even if it thinks this data is local data. 99

99

The reason why I set this option to true 100

100

because once we use the HTTPS bypass caplet 101

101

the data will seem as if it is being sent from our computer. 102

102

So BetterCAP will think these passwords belong to me, 103

103

to my computer and it will not display it to me on screen. 104

104

That's why we are setting it to true. 105

105

So that we can see all of the usernames and the passwords 106

106

sent on the websites that we will downgrade 107

107

from HTTPS to HTTP. 108

108

So I'm gonna save this. 109

109

Control + S and quit it, Control + Q. 110

110

And now we are actually ready to go and use this caplet. 111

111

So in the next lecture, 112

112

I'm gonna show you how to use this caplet 113

113

to downgrade HTTPS connections to HTTP. 114

114

And therefore be able to sniff the URLs, 115

115

the login information and passwords 116

116

that people enter on websites 117

117

that use HTTPS by default.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.