Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Okay, so now that we understand the theory 2
2
behind bypassing HTTPS and we have the correct caplet 3
3
placed in the correct path, 4
4
let's go ahead and use this caplet with Bettercap 5
5
and see how we can downgrade HTTPS to HTTP 6
6
and steal passwords from login pages 7
7
that use HTTPS by default. 8
8
So I'm gonna go to my terminal and I'm gonna use Bettercap 9
9
exactly as I've been using it before. 10
10
So we're doing Bettercap, the name of the program. 11
11
We're giving it our interface after the iface argument, 12
12
we're using the caplet argument to specify a caplet to run 13
13
as soon as we run the program 14
14
and we're running the spoof caplet, 15
15
the one that we built in the previous lecture 16
16
that'll run the ARP spoofing command 17
17
and run the sniffer for us. 18
18
So I'm gonna hit enter and as you can see, 19
19
everything got executed as expected. 20
20
If we do help, we'll see all the running modules 21
21
and we have the ARPspoof and the sniffer running 22
22
with the recon and with the probe. 23
23
So this is exactly what we wanted from our caplet. 24
24
The next thing that we wanna do 25
25
is run the HSTS bypass caplet 26
26
the one that we just downloaded 27
27
and placed in our Bettercap directory. 28
28
So first of all, the HSTS bypass caplet 29
29
is one of many caplets that Bettercap comes with. 30
30
If you want to list all of these caplets, 31
31
you can do caplets.show and as you can see, 32
32
you'll get a list of all of the caplets that you have 33
33
and their location on the system. 34
34
Now, the caplet that we want to run 35
35
is the HSTS hijack couplet. 36
36
This one right here. 37
37
And you can see it's stored in here. 38
38
This is the location where we actually replaced it 39
39
with the one that we downloaded. 40
40
And to run any of these caplets, all you have to do 41
41
is literally just type its name. 42
42
And as usual, you can use the tab to auto complete. 43
43
So to run our caplets right here, all I have to do 44
44
is literally type HS and press tab. 45
45
And as you can see, it'll automatically auto-complete for me 46
46
and type the caplet name. 47
47
Now if I hit enter, this will load the caplet 48
48
with all of its options and it'll run it for me. 49
49
So as you can see, because we don't see any errors, 50
50
this means everything got executed as expected. 51
51
So let's go to the windows machine, browse some HTTPS pages 52
52
and see if we can sniff data, usernames, passwords, and URLs 53
53
that they enter on their computer. 54
54
So I have my windows machine here. 55
55
I have Chrome installed. 56
56
This is the latest version of Chrome 57
57
at the time of recording this lecture, 58
58
which is in April, 2019. 59
59
Now, a really good idea before trying all of these things 60
60
is to remove your browsing data 61
61
because the websites that we're gonna try to access 62
62
might be cached 63
63
and they might be just loaded from your cache. 64
64
This will only happen if you're visiting the same website 65
65
over and over again, mostly when testing. 66
66
Therefore, it's a really good idea to control shift, delete 67
67
and click on clear browsing data. 68
68
Make sure all of this is clicked, 69
69
make sure it's set to all the time and click on clear 70
70
to remove all of it. 71
71
And let's go ahead and go to a website that uses HTTPS. 72
72
So a good example would be linkedin.com. 73
73
And perfect, if you look here at the top, 74
74
you'll see the website is loading over HTTP, not over HTTPS. 75
75
Therefore, we'll be able to see anything the user enters 76
76
in these boxes. 77
77
So let's put a user name. 78
78
Let's set it to zaid@zsecurity.org 79
79
and I'll put our password as 1234567890. 80
80
It doesn't really matter, you can use any password. 81
81
And I'm gonna hit enter to log in. 82
82
This is wrong, so obviously we're getting an error message, 83
83
but if we go back to Kali, as you can see 84
84
we're capturing all of this data 85
85
because it's not being sent over HTTPS anymore. 86
86
It's being sent over HTTP. 87
87
And if you look in here, 88
88
you can see we captured login information. 89
89
It's sent to linkedin.com, 90
90
sent to this specific URL, a login URL 91
91
and you can see the username is zaid@zsecurity.org 92
92
and the password is one, two, three 93
93
all the way up to nine zero. 94
94
So that's really, really good. 95
95
Let's go ahead and test another HTTPS website. 96
96
Let's go to stackoverflow.com. 97
97
Again, you can see on top it's loading over HTTP, not HTTPS. 98
98
So I'm gonna click on login. 99
99
And again I'm gonna put my email zaid@zsecurity.org 100
100
and we'll put our password as 1234567890, hit enter. 101
101
And let's go to the Kali machine again, 102
102
scroll down this time 'cause we're stuck on top. 103
103
And perfect, you can see we have a post request in here. 104
104
It's sent to this specific URL. 105
105
Again, you can see login in the URL. 106
106
You can see the website itself, stackoverflow.com 107
107
and if we scroll down a little bit more 108
108
we can see that the username is zaid@zsecurity.org 109
109
and the password, again, 110
110
one, two, three all the way up to nine zero. 111
111
So that is really, really good. 112
112
Now we can downgrade any HTTPS connection to HTTP 113
113
as long as the target website uses HTTPS, not HSTS. 114
114
So this method will work against pretty much all websites 115
115
that use HTTPS except for the really popular websites 116
116
such as Facebook, Twitter, and so on. 117
117
So let me show you a quick example. 118
118
If I go here and try to go to facebook.com 119
119
you'll see that the website got loaded over HTTPS, 120
120
not over HTTP, 121
121
even though we configured our caplet correctly, 122
122
and even though we're able to downgrade HTTPS connections 123
123
on a lot of websites such as LinkedIn and Stack Overflow. 124
124
This is happening because Facebook is using HSTS 125
125
which is a little bit trickier to bypass. 126
126
In the next lecture we'll talk more about what HSTS is, 127
127
why it's tricky to bypass and how to partially bypass it 128
128
and still get usernames and passwords 129
129
from the websites that implement it 130
130
such as Facebook, Twitter, and so on.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.