All language subtitles for 5. Spying on Network Devices (Capturing Passwords, Visited Websites...etc)

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic Download
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

In the previous lecture, 2

2

we learned how to use BetterCAP 3

3

to run an ARP spoofing attack 4

4

and place ourselves in the middle of the connection 5

5

between a computer and the access point. 6

6

And every time I do this, 7

7

I keep saying this means that all the requests 8

8

and all the responses will flow through our computer, 9

9

which means that we'll be able to see anything 10

10

a user does on the Internet. 11

11

So we should be able to see the URLs, 12

12

the images, the videos, 13

13

the passwords they login with 14

14

or anything they send or receive. 15

15

So right now, we are already in the middle of the connection 16

16

and this data is already flowing through our computer. 17

17

So all we have to do is just use a program 18

18

to capture this data and analyze it. 19

19

Now we can use Wireshark to do that, 20

20

and I will cover this later on in the course, 21

21

but for now I'm gonna use a really nice module 22

22

that comes with BetterCAP, 23

23

that will automatically capture all of this data, 24

24

analyze it and show me the interesting stuff. 25

25

So all we have to do now is to tell BetterCAP 26

26

to capture all of the data 27

27

that is flowing through this computer 28

28

and analyze it for me. 29

29

And to do this, we can use the net.sniff module. 30

30

So you can do help followed by net.sniff 31

31

to see all of the options that you can set for this module. 32

32

But I showed you how to read options and change them, 33

33

so for now I actually wanna run it 34

34

without modifying any of the options, 35

35

so I'm just gonna do net.sniff on. 36

36

So now everything that's gonna flow through this computer 37

37

will be captured and analyzed by the net.sniff module. 38

38

So I'm gonna close this terminal window 39

39

and let's go to the target Windows computer. 40

40

I'm gonna open my web browser 41

41

and we're gonna generate some traffic 42

42

and see if that's gonna be captured by BetterCAP. 43

43

What we're doing right now 44

44

will not work against HTTPS 45

45

but don't worry, 46

46

we'll talk about how to bypass HTTPS later on 47

47

and why this won't work. 48

48

But for now, for testing, 49

49

I'm just gonna to a website called vulnweb 50

50

and I'm gonna include it's link 51

51

in the resources of this lecture. 52

52

So as you can see this is a normal website 53

53

that doesn't use HTTPS. 54

54

It also has a number of links here, 55

55

so if I click, for example, on this link, 56

56

everything is loading fine 57

57

as you can see here. 58

58

But if we go to the Kali machine, 59

59

you'll see that every request that we sent 60

60

was actually captured by this computer. 61

61

So you can do this to any computer 62

62

that is connected to the same network as you, 63

63

whether it's a wired or a wireless network. 64

64

So you can see there were requests sent to Google, 65

65

if we scroll down, 66

66

you will see we made a request 67

67

for this website, vulnweb.com. 68

68

You can also see all of the other files 69

69

that this website loaded. 70

70

So you can see we have a logo loaded here. 71

71

You can see we have a styles file being loaded here. 72

72

Again, if there were more images, 73

73

you'll actually see links to all of the images 74

74

that are being loaded. 75

75

You can see here this is the second link 76

76

that we clicked on, the testphp.vulnweb.com. 77

77

So this is what we have right here, here in the top. 78

78

Now also, let me just go back 79

79

and maybe click on the first one. 80

80

And as you can see, 81

81

this is another website. 82

82

It has the login functionality in here. 83

83

And let's try, for example, 84

84

login with a username. 85

85

Let's set the username to my name, ziad sabih. 86

86

And let's put the password as 1234567890. 87

87

I'm gonna click on Login. 88

88

Again, as you can see, 89

89

we got logged in, no issues at all. 90

90

But if I go back to the Kali computer 91

91

and scroll up, 92

92

as you can see, we captured a login 93

93

that was sent to this website, testhtml5.vulnweb.com. 94

94

Again, this is exactly the website that we have here 95

95

and if you look in here, 96

96

you can see that the username was ziad sabih 97

97

and the password was 123 all the way up to 90. 98

98

So basically the idea that I'm trying 99

99

to get across right now, 100

100

anything that the target computer sends 101

101

or receives right now will be captured by the Kali machine. 102

102

And like I said, we can do this to any computer 103

103

or any phone that is connected to the same network as us, 104

104

whether it's a WiFi or a wired network.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.