mirror of
https://github.com/couchfault/sslstrip2.git
synced 2025-10-29 16:56:59 +00:00
12 lines
625 B
Markdown
12 lines
625 B
Markdown
SSLStrip+
|
||
=========
|
||
|
||
This is a new version of Moxie´s SSLstrip http://www.thoughtcrime.org/software/sslstrip/ with the new feature to avoid HTTP Strict Transport Security (HSTS) protection mechanism.
|
||
|
||
This version changes HTTPS to HTTP as the original one plus the hostname at html code to avoid HSTS. Check my slides at BlackHat ASIA 2014 (OFFENSIVE: EXPLOITING DNS SERVERS CHANGES) for more information.
|
||
|
||
For this to work you also need a DNS server that reverse the changes made by the proxy, you can find it at https://github.com/LeonardoNve/dns2proxy.
|
||
|
||
|
||
Demo video at: http://www.youtube.com/watch?v=uGBjxfizy48
|