Video wird geladen...
Video konnte nicht geladen werden
Public WiFi: Quick demo for 2 devices on the same network 1. SSLstrip + DNS change leads to user input interception for HTTPS with HSTS bypass 2. DNS spoofing redirects user to attacker controlled website More in upcoming "NetHunter Hacker XIII: Overall guide to MITM framework"
539,024 Aufrufe • vor 3 Jahren •via X (Twitter)
10 Kommentare

An attacker can create custom fake access point with internet connection directly from Android smartphone running within a pocket #NetHunter

✅How to prevent being spied on the public wifi Use specific native mobile apps, not browser, to access services that requires you to enter credentials or sensitive data. These apps should use SSL certificate pinning where attacker can't intercept their traffic

Which parts of the HSTS will this be able to circumvent? And in native apps where pinning is being used, can you do any kind of attack to the comms using this approach?

It changes the requested domain by prepending not registered subdomain. Since such subdomain doesn't exist, server will not request browser to use HSTS. If native apps use ssl pinning then it's not possible to use this scenario or intercept such app's traffic without patching it.

Where's the https lock? lol!

SSLStrip stripped it away

It's clearly not https

Shouldn't a HTTPS certification error occur when attempting to open the page?

sigh @UK_Daniel_Card

Cómo lo has conseguido? Los dispositivos modernos requieren de que un certificado sea instalado en el dispositivo para conseguir pasar por alto hsts y poder capturar el trafico vía mitmproxy o burpsuite 🤔. Sslstrip vence hsts?

![[ Turn sound on 🔊 ] I feel guilty for spending more time on this. But boy was it fun! I over engineered it to be a real language learning companion. It supports multiple user profiles, custom system prompt, battery reading, hand-free mode… I even built a launcher for the device, with custom UI framework specifically for this embedded system. And a full iOS companion app to help with setting up wifi, API keys & setting synchronization. This was also the first time I used Claude Design. To my surprise, the output is pretty good! It does require a few iterations though. I used to work at 2 hardware startups and building the software for these devices used to take months. Now with AI, it takes just a couple of day for a pretty decent product. Are you interested in this? I may open source all the code if anyone wants to do the same.](https://image.24vids.com/tw-2085002696139161681/media/HO9q2oOagAAsZLM.jpg)
