Author Topic: HTTPS Everywhere (Firefox addon) protects against SSLStrip attacks  (Read 1357 times)

0 Members and 1 Guest are viewing this topic.

Offline m0l0ko

  • Peasant
  • *
  • Posts: 129
  • Cookies: -4
    • View Profile
I'm practicing MITM attacks on myself (using a BT5 VM as the attacker) and I noticed that when I entered passwords into websites using opera, ettercap sniffed them but when I used firefox, ettercap couldn't sniff anything. I was trying to figure out why that was, then I realised that a plugin I have for firefox (its called HTTPS Everywhere) was forcing firefox to use HTTPS protocol, rendering SSLStrip useless. HTTPS Everywhere is a brilliant addon, it forces firefox to use HTTPS protocol wherever possible so you don't have to do it manually.

Offline offensive

  • NULL
  • Posts: 2
  • Cookies: 0
    • View Profile
Re: HTTPS Everywhere (Firefox addon) protects against SSLStrip attacks
« Reply #1 on: June 03, 2012, 02:56:49 am »
i think sslstrip can capture your password. https everywhere is not problem

Offline m0l0ko

  • Peasant
  • *
  • Posts: 129
  • Cookies: -4
    • View Profile
Re: HTTPS Everywhere (Firefox addon) protects against SSLStrip attacks
« Reply #2 on: June 03, 2012, 03:02:22 am »
You sure about that? I tried get ettercap to sniff my username/password when I entered it into firefox but I couldn't get firefox to go to regular http pages at all, it just redirected to https.

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: HTTPS Everywhere (Firefox addon) protects against SSLStrip attacks
« Reply #3 on: June 03, 2012, 08:12:58 am »
HTTPS use SSL protocol, so SSLStrip is a decoding program that strips encryption from captured data sent with HTTPS. If you couldn't get the password with SSLStrip then you were doing it wrong :D
I too use HTTPS everywhere I can when I am on public networks.