Man In The Middle attack | dSploit | Hack any account - 2017





Hello Android geeks. Most of you guys haven't seen me around here because I just don't know a lot about Android OS and how it works. The MITM (Man In The Middle) attack I'm going to show you is for Android only. The tool is called dSploit and it can be downloaded for free from here: http://www.dsploit.net/. This tool has been around for a few months now but I found this just a couple days ago. I was amazed how efficient and easy to use it is! I'm going to show you an easy trick in this tutorial, how to replace images on websites. So basically every time somone goes to a website (on your LAN), every image on that website will be replaced by a picture of your choice. Hopefully you haven't lost your interest yet. If you did, please post here if you want me to make a tutorial about stealing cookies and passwords. You can steal basically every account with this tool. Let's get started bros.



This is what you're going to need.
- An Android device with at least the 2.3 ( Gingerbread ) version of the OS. ( 2.3 support since v1.0.5b ).
- The device must be rooted
- The device must have a
http://BusyBox full install, this means with every utility installed ( not the partial installation ).
- A Wifi


First thing you need to (obviously) is download the tool. Open your browser with your Android device and head to: http://www.dsploit.net/. After downloading you should know how to install it. If you don't know how to install applications you shouldn't be on the Internet in the first place.

After installing the application, open it. I don't remember if you have to register or not. If it asks you to do something, it will be very simple. The next thing you want to do is select your router. It should look something like this.






Now you should see options like "Port scanner" and "Inspector". The really cool stuff is not here, you need to scroll down and select the MITM.




You should see a lot of great features like "Session hijacker" and "Password sniffer". We're not going to use those this time. Scroll down and select the "Replace images" feature.




Now, it will ask you to choose a picture from your photos or a link. I'll use the link feature but you can use the other one if you like.


Press "Done" and it should start attacking the router. If you want to stop the attack, just press it again and it will stop. Let it run for now. Now, go to your computer (it should be connected to the same wifi) and open up http://imgur.com for example. In my case, the websites I tested this with are looking like this.





Remember to use this tool for educational purposes only. You can get in deep trouble if you hijack cookies or sniff passwords. Doing this in school will end up in a suspension for sure. I am in no way responsible of your actions!






How to hijack cookies

This is almost the same as mentioned method above. You can use password sniffer too but it won't work with https secured pages. The great thing in cookie hijacking is that it works with https pages too. You can basically hijack cookies from ANY site. The bad side is that you can't get their passwords, you just get access to their account.

In the image replacing we scrolled down in the MITM section. This time you will see the "Session hijacker" right after opening the MITM. After opening the session hijacker, you will see a start button, click that. When using password sniffer, the victim has to enter a password while your attack is running. dSploit on the other hand will hijack the cookies without the victim even logging in at the time of the attack. In other words, I can access any account that is logged in after pressing the start button. If you're connected to a public wifi, you will probably get tens of cookies right after clicking the start button. This is the result of five seconds of cookie hijacking on my school's less used wifi.



Just click the cookie you want to grab and dSploit will open you its browser. Remember, don't do anything (too) stupid. If you have any questions, feel free to post here.

Download:

Dsploit: http://www.apkhere.com/down/it.evilsocket.dsploit_1.0.31b_free