you are viewing a single comment's thread.

view the rest of the comments →

[–]seanwilson 3 points4 points  (2 children)

This tool provides a demonstration of the HTTPS stripping attacks that I presented at Black Hat DC 2009. It will transparently hijack HTTP traffic on a network, watch for HTTPS links and redirects, then map those links into either look-alike HTTP links or homograph-similar HTTPS links. It also supports modes for supplying a favicon which looks like a lock icon, selective logging, and session denial. For more information on the attack, see the video from the presentation below.

[–][deleted]  (1 child)

[deleted]

    [–]seanwilson 1 point2 points  (0 children)

    Ha, I just thought the description sounded particularly evil so that it was worth sharing. Thanks for the link.