mram42 Posted July 26, 2014 Share Posted July 26, 2014 Hey peeps, just wanted to let you know about a little writeup I did for getting SSLsplit up and runnning on the WiFi pineapple Mark V. I was using my pineapple on a pentest on a mobile app recently. I wanted to break open the SSL connection the App made to a specific host. Proxy redirection did not work as the app was using non HTTP traffic over the SSL tunnel. So Burp was unable to interpreter the traffic. Here I learned about SSLsplit: a great tool for full SSL traffic decoding regardless of what protocol is used over the SSL tunnel. I wanted to use it on my Pineapple, but was unable to find a how-to. So I made a writeup on how to get it working. Check it out at http://champagneandsecurity.wordpress.com/2014/07/26/sslsplit-on-wifi-pineapple/ Its a non GUI apporach, but it works like a charm and lead to some very interesting results with my app pentest :) I hope it helps others trying to achieve the same. Quote Link to comment Share on other sites More sharing options...
Darren Kitchen Posted July 26, 2014 Share Posted July 26, 2014 Wow, thanks for the contribution! What an excellent write up. I'd love to see an infusion to put a GUI on this, but otherwise fantastic stuff! Quote Link to comment Share on other sites More sharing options...
Guest spazi Posted July 27, 2014 Share Posted July 27, 2014 Thanks for sharing buddy! I'll check it out tonight :D Quote Link to comment Share on other sites More sharing options...
NullNull Posted July 27, 2014 Share Posted July 27, 2014 Very Good! Thanks mram42! Quote Link to comment Share on other sites More sharing options...
theshabobo Posted July 29, 2014 Share Posted July 29, 2014 Totally awesome, I will be adding this to my Hackbox v1.0! Quote Link to comment Share on other sites More sharing options...
Whistle Master Posted August 2, 2014 Share Posted August 2, 2014 (edited) Soon Done ! Edited October 5, 2014 by Whistle Master Quote Link to comment Share on other sites More sharing options...
mram42 Posted October 5, 2014 Author Share Posted October 5, 2014 Just for the archive: an Infusion of SSLSplit was made. You can still use my howto if you want to do it manually, but the Infusion works great and is much easier. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.