MITMf/sslstrip
2014-11-29 18:17:56 +01:00
..
2014-07-07 13:40:49 +02:00
2014-11-29 17:37:42 +01:00
2014-11-29 18:17:56 +01:00
2014-07-07 13:40:49 +02:00
2014-07-07 13:40:49 +02:00
2014-07-07 13:40:49 +02:00
2014-07-07 13:40:49 +02:00
2014-07-07 13:40:49 +02:00
2014-07-24 20:41:13 +02:00
2014-07-07 13:40:49 +02:00
2014-07-07 13:40:49 +02:00
2014-11-29 18:17:56 +01:00
2014-11-29 17:12:21 +01:00
2014-07-07 13:40:49 +02:00
2014-11-29 15:30:43 +01:00

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

SSLStrip+
=========

This is a new version of [Moxie´s SSLstrip] (http://www.thoughtcrime.org/software/sslstrip/) with the new feature to avoid HTTP Strict Transport Security (HSTS) protection mechanism.  
  
This version changes HTTPS to HTTP as the original one plus the hostname at html code to avoid HSTS. Check my slides at BlackHat ASIA 2014 [OFFENSIVE: EXPLOITING DNS SERVERS CHANGES] (http://www.slideshare.net/Fatuo__/offensive-exploiting-dns-servers-changes-blackhat-asia-2014) for more information.  
  
For this to work you also need a DNS server that reverse the changes made by the proxy, you can find it at https://github.com/LeonardoNve/dns2proxy.


Demo video at: http://www.youtube.com/watch?v=uGBjxfizy48