Ethical Hacking - NETWORK PENETRATION TESTING(18)

Session Hijacking

What if the user uses the "remember me" feature?

If the user uses this feature the authentication happens using the cookies and not the user and password, So instead of sniffing the password we can sniff the cookies and inject them into our browser, this will allow us to login to the user's account without using the password.

apt-get install ferret-sidejack

Ethical Hacking - NETWORK PENETRATION TESTING(18)_第1张图片
ferret -i [INTERFACE]

hamster

 

Ethical Hacking - NETWORK PENETRATION TESTING(18)_第2张图片

 

 

Start the hamster

Ethical Hacking - NETWORK PENETRATION TESTING(18)_第3张图片

 

 It  works.

Ethical Hacking - NETWORK PENETRATION TESTING(18)_第4张图片

 

 You can get the cookies on the victim PC and login in as the authorized user.

....

你可能感兴趣的:(Ethical Hacking - NETWORK PENETRATION TESTING(18))