Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
byt3bl33d3r committed Apr 9, 2015
1 parent 74ba7c7 commit f228f30
Showing 1 changed file with 6 additions and 4 deletions.
10 changes: 6 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
SSLstrip+
========

This is just a mirror of the original SSLstrip+ code by Leonardo Nve, which had to be taken down because of a gag law
This is just a mirror of the original SSLstrip+ code by Leonardo Nve, which had to be taken down because of a gag order.

**For this to work you also need a DNS server that reverses the changes made by the proxy, you can find it at https://github.com/singe/dns2proxy**

Description
===========

This is a new version of [Moxie´s SSLstrip] (http://www.thoughtcrime.org/software/sslstrip/) with the new feature to avoid HTTP Strict Transport Security (HSTS) protection mechanism.

This version changes HTTPS to HTTP as the original one plus the hostname at html code to avoid HSTS. Check my slides at BlackHat ASIA 2014 [OFFENSIVE: EXPLOITING DNS SERVERS CHANGES] (http://www.slideshare.net/Fatuo__/offensive-exploiting-dns-servers-changes-blackhat-asia-2014) for more information.

For this to work you also need a DNS server that reverse the changes made by the proxy, you can find it at https://github.com/LeonardoNve/dns2proxy.


Demo video at: http://www.youtube.com/watch?v=uGBjxfizy48

0 comments on commit f228f30

Please sign in to comment.