84matte84 Posted December 14, 2014 Share Posted December 14, 2014 Hi everybody guys, this is my first post here and I am quite exited...I got my pineapple today...yay!!! :D However I am sad because I did not have any chance to work it yet... I followed many different guides on the web and basically what I did is: 1)booted it and upgraded the firmware 2)set up the SSID passwd etc etc 3)installed the sslstrip infusion 4)started karma 5)started the sslstrip however I did not have any chance to hook the login/passwd process executed on my laptop as a test....and it seems (from the log) that I wasn't neither able to detect any kind of traffic... I am kinda confused....could you please help me understanding where and what I am doing wrong? My best Matteo Quote Link to comment Share on other sites More sharing options...
czepeda Posted December 14, 2014 Share Posted December 14, 2014 Hey I am on your boat. I just got mine too. I am able to harvest some Passwords using Internet Explorer but when it comes to Chrome or Mozilla it doesn't SSL strip anything? Is it that way for you too? Quote Link to comment Share on other sites More sharing options...
m40295 Posted December 14, 2014 Share Posted December 14, 2014 (edited) try something older with weak security. Myspace for example. Places like facebook wont work I use a app on my phone called textnow for sms. and with sslstrip running I can read my messages in the log Edited December 14, 2014 by m40295 Quote Link to comment Share on other sites More sharing options...
czepeda Posted December 14, 2014 Share Posted December 14, 2014 What about as far as Chrome and Mozilla? Are they too secure now? Quote Link to comment Share on other sites More sharing options...
m40295 Posted December 14, 2014 Share Posted December 14, 2014 (edited) Not sure. I focus on mobile browsers. I use chrome on android Good read. http://en.m.wikipedia.org/wiki/HTTP_Strict_Transport_Security Edited December 14, 2014 by m40295 Quote Link to comment Share on other sites More sharing options...
czepeda Posted December 14, 2014 Share Posted December 14, 2014 I will definitely read that. When you say you focus on mobile browsers, are you saying the SSL strip works well on phones? Quote Link to comment Share on other sites More sharing options...
m40295 Posted December 14, 2014 Share Posted December 14, 2014 (edited) Yep for me. check pm.top right corner Edited December 14, 2014 by m40295 Quote Link to comment Share on other sites More sharing options...
84matte84 Posted December 14, 2014 Author Share Posted December 14, 2014 Thank you guys for your replies... I did not try with Internet Explorer but the problem is that my log is empty... I mean....it seems that I am not MITM anything!!! I would like to leave it running for some hours because I can see different SSID from my flat BUT, I have not found how to save the log yet....each time I open the SSLSTRIP window the log is empty and the "autorefresh" is off (even though I set it ON when I closed the infusion).... Is there a way to save the log to the SD or to an USB drive in order to unplug it from the pineapple and plug it into a laptop to read it? Mat Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.