FaceNiff will not display anything, if you don't have target ( who is using http to access a web account).
If the victim is using https, you can try tapping on "SSL Strip"
to force the victims browser to fall back on http. I think, SSL
striping will not work on Facebook and blogger , because they are using
HSTS (HTTP Strict Transport Security) to protect against downgrade
attacks.
At the time of testing this app, I found that the website vk.com also known as vkontakte.ru is running on http and can use FaceNiff to steal session cookies.
Tap on the unencrypted sessions displayed on the FaceNiff and use the stock browser to access the webpage.
Now you have the victims web account. Well done! (Remember: If the victim logged out from the account, you will also be logged out automatically)
No comments:
Post a Comment