Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now in this lecture, 2
2
I wanna show you how to use Wireshark 3
3
to discover data sent through forms, 4
4
whenever someone fills up a form. 5
5
And obviously, this will allow us 6
6
to get usernames and passwords 7
7
if people log in to their accounts. 8
8
So, I'm already running BetterCAP, 9
9
so I'm already the man in the middle. 10
10
And in Wireshark here, I'm just gonna start a new capture. 11
11
So I'm gonna continue without saving this one. 12
12
The filter is already set to HTTP 13
13
so it's only gonna show me HTTP packets in here. 14
14
And I'm gonna go to a target website in here, 15
15
so let's go to vulnweb.com. 16
16
Now keep in mind, like I said, 17
17
you have to be loggin' in to a HTTP page, 18
18
but that's fine because we already learned 19
19
how to bypass HTTPS, and even partially bypass HSTS. 20
20
So, I'm gonna be logging into a website 21
21
that just uses HTTP here, because it's just simpler, 22
22
and we've already learned how to bypass HTTPS and HSTS, 23
23
so there's no point of repeating that. 24
24
We're logging in with a username that is set to admin. 25
25
I'm gonna get the password to 123abc. 26
26
I'm gonna click on Login, 27
27
and this should have been captured by Wireshark. 28
28
Now let's go ahead and actually try this 29
29
with a website that uses HTTPS. 30
30
So let's go to stackoverflow.com. 31
31
Again, as you can see, 32
32
as long as the website gets downgraded to normal HTTP, 33
33
then we'll be able to capture the data sent 34
34
to and from this website. 35
35
So, we're just going to log in. 36
36
Put the username, we'll put it to zaid@zedsecurity.org, 37
37
and then we're gonna put the password. 38
38
So we'll just do 123123abc. 39
39
And let's go back to Wireshark, 40
40
and see how we can discover the username and the password. 41
41
So first of all, I'm gonna stop the capture. 42
42
And what we wanna look for is POST requests. 43
43
So you see in here this request right here was POST, 44
44
for example, and here it was GET. 45
45
Now forms are usually sent over POST, 46
46
especially login forms. 47
47
So if you're looking for login information, 48
48
you wanna look for POST in here. 49
49
So, going down we can see we have a POST request in here. 50
50
Now I'm gonna click here to actually show less information, 51
51
so it's easier for us to see. 52
52
So we can see this POST was sent to Google. 53
53
We're not interested in that, 54
54
we're looking for stuff that was sent to Vulnweb. 55
55
So I'm gonna keep going. 56
56
We can see we have a POST request here 57
57
to a login page, so this is definitely interesting. 58
58
Now, if we look down, let me just make this smaller. 59
59
So if we look down here, and look at the HTML form data, 60
60
you can see that we have a username here, 61
61
submitted to testhtml5.vulnweb.com. 62
62
The username is admin, and the password is 123abc. 63
63
Now if we scroll down again looking for POST requests, 64
64
you can see we have a POST request 65
65
for a page called users login. 66
66
So again, very, very interesting. 67
67
If we click on this, you'll see, if we scroll down, 68
68
you'll see we have the email, zaid@zedsecurity.org, 69
69
and the password 123123abc. 70
70
Again, this just goes to show you 71
71
that with Wireshark, you'll be able to capture everything. 72
72
Now this can actually be very, very useful, 73
73
because I noticed that BetterCAP is great 74
74
at sniffin' passwords. 75
75
And it pretty much gets you the passwords all the time, 76
76
but in the odd cases, sometimes it was failing 77
77
to filter the username and the password for me. 78
78
So, with Wireshark you'll actually be able to get everything 79
79
that passes through your interface. 80
80
So what you could actually do is you can just go 81
81
to your caplet that we always use, the spoof caplet. 82
82
This one right here. 83
83
Open it with the Text Editor. 84
84
And as you know, in this caplet, 85
85
we turn on our sniffer in here, 86
86
so we set the sniff.local to true, 87
87
and then we turn it on. 88
88
But before turning it on, 89
89
you can actually set the net.sniff.output 90
90
to a location for a file that'll contain everything 91
91
that BetterCAP captures. 92
92
So you won't actually have to start Wireshark 93
93
while BetterCAP is working. 94
94
You can just, in here, specify a place. 95
95
So for example, let's say root/capturefile.cap. 96
96
And then, when you run your spoof caplet, 97
97
it'll turn on the probe, turn on the recon, 98
98
run your spoofing attack, 99
99
putting you in the middle of the connection. 100
100
It'll run the sniffer as well, 101
101
and it'll store everything that BetterCAP captures 102
102
in a capture file. 103
103
Then, all you'll have to do is come here, 104
104
go to File, Open, and open the file that you captured, 105
105
and analyze it, as I'm doing right now. 106
106
So this can be very, very useful also 107
107
if you don't have a lot of resources on your computer, 108
108
or if you have a small laptop, or even a phone. 109
109
And you capture data with it, 110
110
store everything in a capture file, 111
111
and then just open it in here in Wireshark and analyze it. 112
112
Now finally, before I finish this lecture, 113
113
because all we're talkin' about right now is filtering data, 114
114
a really, really useful feature when filtering data 115
115
is the Ctrl+F feature, the Find. 116
116
So you can just press Ctrl+F from your keyboard, 117
117
this'll open this bar right here, this search bar, 118
118
which you can use to find anything 119
119
within the captured packets. 120
120
So, first of all, I'm gonna set the search 121
121
to search within the packet details. 122
122
I'm gonna keep this to Narrow & Wide. 123
123
In here, I'm gonna set this to Strings, 124
124
so that it looks for normal text. 125
125
And for example, let's say I'm looking for logins 126
126
that a person named Zaid has attempted, 127
127
all I have to do is just type Zaid. 128
128
And if I hit Enter. 129
129
And as you can see, it's taken us to the login attempt 130
130
when I logged in to Stack Overflow. 131
131
Or let's say you're looking for login attempts 132
132
by a person named admin or for a user named admin. 133
133
Again, if I hit Enter, it's gonna take me to the first time 134
134
an occurrence of the word admin happened, 135
135
which is in here. 136
136
It doesn't really contain any useful information, 137
137
but I can just click on Find to find the next packet 138
138
that contained the word admin. 139
139
Again, this packet doesn't really contain anything useful. 140
140
We can go next. 141
141
We'll actually have to go to the end of the file and go up, 142
142
because that was the first thing that we logged in, 143
143
so I'm just gonna keep clicking on next. 144
144
And right here we have the POST request for the admin. 145
145
And if we go down again, as you can see, 146
146
we have the username as admin and the password as 123abc. 147
147
So this feature can be very, very useful 148
148
to help you find what you're looking for. 149
149
Whether you're looking for a specific login name. 150
150
Whether you're looking for a specific tag, 151
151
a specific file, and so on.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.