Hello
Android geeks. Most of you guys haven't seen me around here because I
just don't know a lot about Android OS and how it works. The MITM (Man
In The Middle) attack I'm going to show you is for Android only. The tool is called dSploit and it
can be downloaded for free from here: http://www.dsploit.net/.
This tool has been around for a few months now but I found this just a
couple days ago. I was amazed how efficient and easy to use it is! I'm
going to show you an easy trick in this tutorial, how to replace images
on websites. So basically every time somone goes to a website (on your
LAN), every image on that website will be replaced by a picture of your
choice. Hopefully you haven't lost your interest yet. If you did, please
post here if you want me to make a tutorial about stealing cookies and
passwords. You can steal basically every account with this tool. Let's
get started bros.
This is what you're going to need.
- An Android device with at least the 2.3 ( Gingerbread ) version of the OS. ( 2.3 support since v1.0.5b ).
- The device must be rooted
- The device must have a http://BusyBox full install, this means with every utility installed ( not the partial installation ).
- A Wifi
First thing you need to (obviously) is download the tool. Open your browser with your Android device and head to: http://www.dsploit.net/.
After downloading you should know how to install it. If you don't know
how to install applications you shouldn't be on the Internet in the
first place.
After installing the application, open it. I don't remember if you have
to register or not. If it asks you to do something, it will be very
simple. The next thing you want to do is select your router. It should
look something like this.
Now you should see options like "Port
scanner" and "Inspector". The really cool stuff is not here, you need to
scroll down and select the MITM.
You should see a lot of great features
like "Session hijacker" and "Password sniffer". We're not going to use
those this time. Scroll down and select the "Replace images" feature.
Now, it will ask you to choose a picture
from your photos or a link. I'll use the link feature but you can use
the other one if you like.
Press "Done" and it should start attacking
the router. If you want to stop the attack, just press it again and it
will stop. Let it run for now. Now, go to your computer (it should be
connected to the same wifi) and open up
http://imgur.com for example. In my case, the websites I tested this with are looking like this.
Remember
to use this tool for educational purposes only. You can get in deep
trouble if you hijack cookies or sniff passwords. Doing this in school
will end up in a suspension for sure. I am in no way responsible of your
actions!
How to hijack cookies
This is almost the same as mentioned method above. You can use password sniffer too but it won't work with https secured pages. The great thing in cookie hijacking is that it works with https pages too. You
can basically hijack cookies from ANY site. The bad side is that you
can't get their passwords, you just get access to their account.
In the image replacing we scrolled down in
the MITM section. This time you will see the "Session hijacker" right
after opening the MITM. After opening the session hijacker, you will see
a start button, click that. When using password sniffer, the victim has
to enter a password while your attack is running. dSploit on the other
hand will hijack the cookies without the victim even logging in at the
time of the attack. In other words, I can access any account that is
logged in after pressing the start button. If you're connected to a
public wifi, you will probably get tens of cookies right after clicking
the start button. This is the result of five seconds of cookie hijacking
on my school's less used wifi.
Just
click the cookie you want to grab and dSploit will open you its
browser. Remember, don't do anything (too) stupid. If you have any
questions, feel free to post here.
Download:
Dsploit: http://www.apkhere.com/down/it.evilsocket.dsploit_1.0.31b_free