Results 1 to 3 of 3

Thread: Ettercap doesn't work with SSL anymore?

  1. #1
    Just burned his ISO
    Join Date
    Dec 2006
    Posts
    10

    Default Ettercap doesn't work with SSL anymore?

    I'm using Bactrack 3.0 final. Whenever I ARP poison my network with ettercap and then access a SSL protected website, the website won't load at all, and instead displays "There is a problem with the security certificate for this website." Is there something I'm overlooking, or was this exploit fixed?

  2. #2
    Member imported_pynstrom's Avatar
    Join Date
    May 2008
    Posts
    143

    Default

    It's not "fixed". When you access the ssl site and receive the warning there should also be a link allowing you to continue to the page anyway. Internet Explorer I believe used to just pop an alert window telling the victim about the security warning, newer versions now redirect to a security warning page. If the victim chooses to continue ettercap should still work just fine.
    When hungry, eat your rice; when tired, close your eyes. Fools may laugh at me, but wise men will know what I mean. -- Lin-Chi
    - - - - - - - -
    I slept once, it was a Tuesday.

  3. #3
    Just burned his ISO
    Join Date
    Dec 2006
    Posts
    10

    Default

    Awesome! Yeah, it still works, it's just that browsers have changed the way they warn users, making this method near useless now. Instead of just a popup warning that tells you to click yes to continue, you get a big scary looking sign that says the SSL cert can't be verified. The text you have to go ahead anyways is very small and at the bottom. I didn't even notice it at first, because on Google Chrome the text says "Set up an exception." instead of "click here to continue". With this new change to browsers, I'm willing to bet far few people will skip past the warning.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •