Strip SSL security with a man-in-the-middle attack
Darren demonstrates a little man-in-the-middle attack using SSLStrip, an epic tool for removing that pesky encryption from your victims browsing session. Go from secure site to clear-text passwords in one simple step.
Moxie Marlinspike’s SSLStrip, released at Blackhat/DEFCON this year, is a tool that transparently hijacks HTTP traffic and redirects HTTPS links to look-alike HTTP links. While this description barely scratches the surface, Darren’s segment takes a closer look including a pracitcal demonstration of a man-in-the-middle attack using arpspoof and a little luck with remote-exploit’s BackTrack 4 penetration testing distribution.


[...] This post was mentioned on Twitter by Abhishek Mathur and Gurdip Singh, Knut. Knut said: Strip SSL security with a man-in-the-middle attack http://bit.ly/7aA4qR [...]
First of all, hello to everyone from Italy.
I appreciate a lot your always interesting and exhaustives hacking videos, but i punctualize that SSLStrip is unuseful without IPTables because of “transparently hijacks HTTP traffic and redirects HTTPS links to look-alike HTTP links” wouldn’t be possibile in absence of that tool; Without IPTables, SSLStrip is reduced to nothing more than an easy sniffer.
Social comments and analytics for this post…
This post was mentioned on Twitter by rebelk0de: RT @LinuxMS: Strip SSL security with a man-in-the-middle attack http://bit.ly/7aA4qR...
ALCOHOL ABUSE!!! lol!