How Hackers Use DNS Spoofing to Phish Passwords (WiFi Pineapple Demo)

Поділитися
Вставка
  • Опубліковано 17 тра 2024
  • @AlexLynd demonstrates how DNS Spoofing & DNS Cache Poisoning can be used to phish your online passwords. This demo uses a WiFi Pineapple to create a Rogue Access Point that can intercept & modify WiFi traffic.
    This video is sponsored by PCBWay: www.pcbway.com
    Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Buy a WiFi Pineapple: shop.hak5.org/products/wifi-p...
    Pineapple Rogue AP / Mitm: • Create Rogue Networks ...
    Nginx Setup Video: • HakByte: Learn Web Hos...
    Pineapple Setup Guide: docs.hak5.org/wifi-pineapple
    Phishing Page Demo: gist.github.com/AlexLynd/7fcc...
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Alex's Twitter: / alexlynd
    Alex's Website: alexlynd.com
    Alex's GitHub: github.com/AlexLynd
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Chapters:
    Intro @AlexLynd 00:00
    What is DNS? 00:19
    DNS Cache Poisoning 00:54
    DNS Attack Overview 01:18
    Tools You'll Need 01:37
    PCBWay Ad 01:43
    Pineapple Setup 01:57
    Rogue AP Overview 02:16
    Modifying DNS Records 03:33
    Clear DNS Cache 05:42
    Disclaimer and Overview 05:57
    Setting up a Webserver 06:28
    Phishing Page Overview 07:25
    Attack Demo 07:50
    Mitigating Attacks 08:27
    Outro 08:46
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Our Site → www.hak5.org
    Shop → hakshop.myshopify.com/
    Subscribe → ua-cam.com/users/Hak5Darr...
    Support → / threatwire
    Contact Us → / hak5
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • Наука та технологія

КОМЕНТАРІ • 39

  • @yunggoofy5535
    @yunggoofy5535 Рік тому +38

    Definitely need more pineapple guides

    • @Davesayer1013
      @Davesayer1013 Місяць тому

      Did you get anymore information?

  • @juliusrowe9374
    @juliusrowe9374 Рік тому +2

    Super dope tutorial Alex! Very informative too!

  • @endlessoul
    @endlessoul Рік тому

    Love the Pineapple videos!

  • @ethansimmons82
    @ethansimmons82 Рік тому +1

    I really like the hosts trick. Thanks for that!

  • @Kattakam
    @Kattakam Рік тому

    Great work! Cheers

  • @kapzvara5732
    @kapzvara5732 Рік тому

    Great video thanks for this will have to buy a wifi pinapple as well the OMG Cable for my next project :)

  • @ecwnikos
    @ecwnikos Рік тому

    thanks for the info mr alex

  • @ironmanlegion3590
    @ironmanlegion3590 Рік тому

    Hi see you got version 2.0.0 firmware on the pineapple, i only find 1.1.1 on your home page, how do i get the newest version?

  • @sagetajr
    @sagetajr Рік тому

    Can u show us how would the built in terminal in the pineapple be used?

  • @sagetajr
    @sagetajr Рік тому +1

    Can u continue to utilize the pineapple wifi. How do i add storage to my pineaaple

  • @melvinpatomendoza
    @melvinpatomendoza Рік тому

    It is even more sophisticated if theres a telco employee insider.

  • @Light_is_god
    @Light_is_god 7 місяців тому

    i love the way u don't say for equcational purpose :)

  • @systembreaker4651
    @systembreaker4651 Рік тому

    what is your laptop please

  • @birhon
    @birhon 6 місяців тому +2

    most browsers counter this pretty simply by detecting an unusual IP routing

  • @SecurityTalent
    @SecurityTalent Рік тому

    Great

  • @Kennethlumor
    @Kennethlumor Рік тому

    Sir please and please I request you create a video on how to hide payload under PDF file

  • @IamTheWaveFunction
    @IamTheWaveFunction Рік тому

    How do get rid of all these penguin ghost and fire goblins?

  • @mohamadsh9653
    @mohamadsh9653 11 місяців тому +3

    This method will no longer work with new updates of browsers. SSLStrip will no longer function due to the implementation of SSL/TLS. Instead of the fake login page, users will see a warning message

    • @ao4514
      @ao4514 7 місяців тому

      I'm pretty sure that there are other ways to poison a Dns!

  • @jeffinaughe3448
    @jeffinaughe3448 Рік тому

    Does it works only for wifi pineapple? Or any wifi network?

    • @MrUncleLeon
      @MrUncleLeon Рік тому +1

      you can use openwrt too or any home router with custom firmware

    • @jeffinaughe3448
      @jeffinaughe3448 Рік тому +1

      @@MrUncleLeon thanks bruh 🙏

  • @donjulioott
    @donjulioott Рік тому +1

    VPN sponsorship needed

  • @youngkingjordon5546
    @youngkingjordon5546 8 місяців тому

    sad i can never get my hands on one

  • @ddavidmelo
    @ddavidmelo Рік тому +3

    What kind of browser are you using on that phone? Must be a good one. This method does not work ....

    • @emmy7279
      @emmy7279 Рік тому

      I think he use a private windows of browser, if not , it doesn't work.

  • @Just4YoutubeDE
    @Just4YoutubeDE Рік тому +3

    I expected a more elegant way to get the password

  • @midimusicforever
    @midimusicforever Рік тому +1

    pain apple!

  • @user-uz4ti5zs8z
    @user-uz4ti5zs8z 6 місяців тому

    EH ALEX ITS BOY WTF IS GOING ON, THE C'S... AND THE INVESTIGATOR SAID YOUR MOM PAST AWAY!? WTF? ELUWENE BOY FROM KALIHI HAWAII OAHU

  • @animal9470
    @animal9470 8 місяців тому

    Next time make this more realistic. Not impressed

  • @mnageh-bo1mm
    @mnageh-bo1mm Рік тому +2

    Lmao No That No longer works silly , TLS much ? No ?

    • @dkryptonut
      @dkryptonut Рік тому

      throw in HSTS on top of that just for good measure

  • @CallousCoder
    @CallousCoder Рік тому +7

    Amateurish! Who trusts an unsigned webpage these days? Hell, every browser warns you for it!

  • @gamebnayename6548
    @gamebnayename6548 Рік тому

    Hey I need some urgent help
    One unknown person is harrasing me and now he deleted his account on insta I want to know his phone Or location associated with that account