This forum is in archive mode. You will not be able to post new content.

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - hightower

Pages: [1]
1
Hi, I'm trying to sidejack my yahoo.com email account. I go into kali, start wireshark, login to my mail, and save the wireshark capture to MyLogin.pcap.

I then clear all browser (iceweasel) history, start Ferret with -r MyLogin.pcap, start hamster, set my browser to use 127.0.0.1:1234 as a proxy (for all protocols) and go to http://hamster.

I can select my ip addr and see all the captured cookies. If I click on www.yahoo.com, this diverts to https://www.yahoo.com and I get "Server not found" in Iceweasel. It's the same for any site that diverts to https. If the site stays on http I'm fine.

If I then try and get to any https site directly in Iceweasel I get the same "Server not found" error until I turn off the hamster proxy.

I really want to get this sidejacking working, is there any solution to this please? I've been trying for about six hours so far today.

Thx a lot for any help, HT.

2
Why you haven't tried it yet? Just modify your browser cookies with any addon

Just trying to really understand what's happening before I go for it. This might be BS (hey, I'm a n00b :)) but I don't want to messup the session before I'm good enough to use it.

Burpsuite can do that.
I suggest you read this:
https://evilzone.org/high-quality-tutorials/session-hijacking-evilzone/
(shameless self promotion :P)

Cheers mate, nice tutorial! Reckon I'm getting there.

Looks like the screenshots aren't working on the tutorial at the moment?

Staff note: Don't double post, use the modify button.

3
Beginner's Corner / can I hijack webmail session from info in a pcap file?
« on: December 19, 2015, 03:59:24 PM »
Hey all, I'm working on a challenge to extract as much info from a pcap file as possible.

The file definitely shows the user was in yahoo mail and I think that's the target.

Yahoo is all https now, so is it possible to hijack the account (it's a test account, not someones personal mail) with the cookie in the pcap file?

Apols if this is a really dumb question, I'm a total noob.

Cheers, HT.

Pages: [1]


Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.