Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - hightower

Pages: [1]
1
Hi, I'm trying to sidejack my yahoo.com email account. I go into kali, start wireshark, login to my mail, and save the wireshark capture to MyLogin.pcap.

I then clear all browser (iceweasel) history, start Ferret with -r MyLogin.pcap, start hamster, set my browser to use 127.0.0.1:1234 as a proxy (for all protocols) and go to http://hamster.

I can select my ip addr and see all the captured cookies. If I click on www.yahoo.com, this diverts to https://www.yahoo.com and I get "Server not found" in Iceweasel. It's the same for any site that diverts to https. If the site stays on http I'm fine.

If I then try and get to any https site directly in Iceweasel I get the same "Server not found" error until I turn off the hamster proxy.

I really want to get this sidejacking working, is there any solution to this please? I've been trying for about six hours so far today.

Thx a lot for any help, HT.

2
Why you haven't tried it yet? Just modify your browser cookies with any addon

Just trying to really understand what's happening before I go for it. This might be BS (hey, I'm a n00b :)) but I don't want to messup the session before I'm good enough to use it.

Burpsuite can do that.
I suggest you read this:
https://evilzone.org/high-quality-tutorials/session-hijacking-evilzone/
(shameless self promotion :P)

Cheers mate, nice tutorial! Reckon I'm getting there.

Looks like the screenshots aren't working on the tutorial at the moment?

Staff note: Don't double post, use the modify button.

3
Beginner's Corner / can I hijack webmail session from info in a pcap file?
« on: December 19, 2015, 03:59:24 pm »
Hey all, I'm working on a challenge to extract as much info from a pcap file as possible.

The file definitely shows the user was in yahoo mail and I think that's the target.

Yahoo is all https now, so is it possible to hijack the account (it's a test account, not someones personal mail) with the cookie in the pcap file?

Apols if this is a really dumb question, I'm a total noob.

Cheers, HT.

Pages: [1]