Jump to content

Urieal

Active Members
  • Posts

    29
  • Joined

  • Last visited

Posts posted by Urieal

  1. After reading countless threads about SSLSTRIP not working on systems such as Safari, Firefox, and Chrome

    I wanted to inquire about something that was released at Defcon Asia...

    SSLSTRIP 2 and DNS2PROXY

    https://github.com/LeonardoNve/sslstrip2

    This is a new version of Moxie´s SSLstrip with the new feature to avoid HTTP Strict Transport Security (HSTS) protection mechanism.
    This version changes HTTPS to HTTP as the original one plus the hostname at html code to avoid HSTS. Check my slides at BlackHat ASIA 2014
    OFFENSIVE: EXPLOITING DNS SERVERS CHANGES for more information. For this to work you also need a DNS server that reverse the changes made
    by the proxy, you can find it at
    https://github.com/LeonardoNve/dns2proxy. Demo video at: http://www.youtube.com/watch?v=uGBjxfizy48

    The DNS Proxy I am having a really hard time following the instructions, I've tried to contact the developer for clarification but no luck.
    Anyone else care to chime in on how to setup dns2proxy? - > Also is there anyone willing to take on the challenge on adding this as an infusion
    to the pineapple?

    My understanding is this would allow you to compromise all browsers such as Safari, Chrome, and Firefox?
    The demo video interestingly enough shows quite vividly proof of concept -- just trying to figure out how to do this?

    I'm running a few Kali Linux machines, can someone clarify how I'm supposed to setup the DNS proxy?

    To the ENTIRE Hak5 Team;
    Thankyou for working on a device that is truly amazing and endless with opportunity. We are only limited by our creativity when it comes to deployment with this awesome device.
    I took it upon myself to invest in all the bells and whistles that came with the Mark 5.


    Lets talk about build quality - FIRST CLASS!
    This thing is scary - To the untrained eye you wouldn't have ANY idea what it is...
    To the trained idea, the only term that comes to mind is pwned and operated.

    PineAP:


    ... so thats what Dogma does -- and thats why karma doesn't work as expected anymore :D -- Soooo many questions on this forum could be answered by watching this regarding Karma..

    Chris Haralson
    https://www.youtube.com/channel/UCK15ED34btB3NZznGIXQuwA
    This guys videos and guides are first class - aimed at people with my skill sets I really couldn't ask for anything to be clearer.
    I am anxiously awaiting your future guides and videos.. (*I check back everyday*).

    My office :D
    And a snazzy little pic of some pineapples....

    post-48383-0-35876700-1409331153_thumb.j

    post-48383-0-66035800-1409331169_thumb.j

×
×
  • Create New...