DSploit
This is what we have under the MITM submenu:
Password sniffing
Session hijack
Redirect traffic
This feature can be used both for fun or profit. For fun, you can redirect all the victim traffic to http://www.kittenwar.com/. For-profit, you can redirect your victim to phishing pages.Replace images, videos
I think this is just for fun here. Endless Rick Rolling possibilities.Script injection
This is mostly for profit. client-side injection, drive-by-exploits, endless possibilities.Custom filter
If you are familiar with ettercap, this has similar functionalities (but dumber), with string or regex replacements. E.g. you can replace the news, stock prices, which pizza the victim ordered, etc. If you know more fun stuff here, please leave a comment (only HTTP scenario - e.g. attacking Facebook won't work).Additional fun (not in DSploit) - SSLStrip
From the MITM section of DSploit, I really miss the SSLStrip functionality. Luckily, it is built into the Pwn Pad. With the help of SSLStrip, we can remove the references to HTTPS links in the clear text HTTP traffic, and replace those with HTTP. So even if the user checks the secure login checkbox at freemail.hu, the password will be sent in clear text - thus it can be sniffed with DSniff.HTML source on the client-side without SSLstrip:
HTML source on the client-side with SSL strip:
With EvilAP, SSLStrip, and DSniff, the password can be stolen. No hacking skillz needed.
Lessons learned here
If you are a website operator where you allow your users to login, always:- Use HTTPS with a trusted certificate, and redirect all unencrypted traffic to HTTPS ASAP
- Mark the session cookies with the secure flag
- Use HSTS to prevent SSLStrip attacks
- Don't trust sites with your confidential data if the above points are not fixed. Choose a more secure alternative
- Use HTTPS everywhere plugin
- For improved security, use VPN
And last but not least, if you like the DSploit project, don't forget to donate them!
More articles
- Hacker Tools Github
- Pentest Tools Free
- New Hacker Tools
- How To Hack
- Growth Hacker Tools
- Pentest Tools Alternative
- Nsa Hacker Tools
- Pentest Tools For Mac
- Pentest Reporting Tools
- Hacking Tools Download
- Pentest Tools For Mac
- Growth Hacker Tools
- Hacker Tools For Windows
- Pentest Tools For Ubuntu
- Hackers Toolbox
- Black Hat Hacker Tools
- Hak5 Tools
- How To Hack
- Pentest Tools For Ubuntu
- Hak5 Tools
- Hacking Tools Usb
- Hacker Tools Github
- Underground Hacker Sites
- Hacking Tools For Kali Linux
- World No 1 Hacker Software
- Hackers Toolbox
- Hacking Tools Software
- Hacks And Tools
- Hacking Tools Windows 10
- Hacker Security Tools
- Bluetooth Hacking Tools Kali
- How To Make Hacking Tools
- Pentest Tools Android
- Hacker Tools 2020
- Install Pentest Tools Ubuntu
- Hacking Tools And Software
- Hacking Apps
- Wifi Hacker Tools For Windows
- Easy Hack Tools
- Pentest Tools For Mac
- Hack Tool Apk No Root
- Hacking Tools For Pc
- Hack Tools For Windows
- Hacking Tools Free Download
- Hacker Tools For Mac
- Hack Tools Github
- Hacking Tools Kit
- Hacker Tools For Mac
- Growth Hacker Tools
- Hacks And Tools
- Hack Rom Tools
- What Are Hacking Tools
- Hack Tools
- Tools 4 Hack
- Blackhat Hacker Tools
- Hacker Techniques Tools And Incident Handling
- Hacking Tools For Kali Linux
- Hack Tools For Pc
- Hacking Tools For Windows Free Download
- Top Pentest Tools
- Hack Tool Apk
- Hacker Hardware Tools
- Tools For Hacker
- Pentest Tools Port Scanner
- Hacker Tool Kit
- Growth Hacker Tools
- Pentest Tools Url Fuzzer
- Pentest Tools Tcp Port Scanner
- Hack Rom Tools
- Install Pentest Tools Ubuntu
- Beginner Hacker Tools
- Hacking Tools 2019
- Pentest Automation Tools
- Hacker Tools For Ios
- Pentest Tools Github
- Hacker Techniques Tools And Incident Handling
- Hack Tool Apk No Root
- Hacker Tools Apk Download
- Hack Tools Pc
- Hacking Tools For Kali Linux
- Hacking Apps
- Hacking Apps
- Pentest Automation Tools
- Computer Hacker
- Hacker Tools Linux
- Hacking Tools For Pc
- Pentest Tools Github
- Hack Tools Online
- Android Hack Tools Github
- Hack Website Online Tool
- Hack Tool Apk No Root
- Termux Hacking Tools 2019
- What Is Hacking Tools
- Hack Tools For Games
- Hack Tools 2019
- Pentest Tools Github
- Growth Hacker Tools
- Hacker Tools Apk Download
- Hack Tools Mac
- Ethical Hacker Tools
- Underground Hacker Sites
- Hacking Tools For Pc
- Hacker Tools Free
- Hacker Tools For Mac
- Hack Tools For Windows
- Hacking Tools Kit
- Hacking Tools Windows
- Hacker Techniques Tools And Incident Handling
- Hacking Tools For Pc
- Pentest Tools Website Vulnerability
- Hacking Tools Pc
- Ethical Hacker Tools
- Pentest Tools For Android
- Hacker Tools List
- What Are Hacking Tools
- Pentest Tools Download
- Hacking Tools And Software
- New Hacker Tools
- Hack Tool Apk
- Hack Tools For Windows
- Black Hat Hacker Tools
- What Are Hacking Tools
- Hack Website Online Tool
- Pentest Tools Linux
- Game Hacking
- What Are Hacking Tools
- Pentest Recon Tools
- Pentest Box Tools Download
- Pentest Tools Port Scanner
- Hacker Tools For Pc