HackTown

Cyber Criminal University - Home

You are not logged in. You will only be able to access the courses in GREEN from the course list.

Chapter 1The Introduction Chapter 2Pre-Requisites Chapter 3IP Address Chapter 4Wi-Fi Routers Chapter 5Looking for Targets Chapter 6Brute Force Chapter 7Get up to date Chapter 8Who's DAT MiTM? Chapter 9Methods to Rule Chapter 10Network Fuckery ConclusionEnd of course


ACT II - Network and MiTM attacks
The Conclusion

You should feel comfortable with launching MiTM attacks against specific targets on the same network as you. The more you practice at these new found skills the better you'll become at launching these types of attacks and determining the best method that works for you. It's always best to test them on yourself to ensure how a target will be prompted from your attacks and see what needs to be tweaked.

Remember, you want to put effort into creating the webpage that people are being re-directed to and make it as professional and relevant looking as possible. Social engineering is key here when developing your attack so put effort into your own landing page.

Today's modernized Internet and web browsers have made MiTM attacks somewhat useless when trying to "sniff" credentials over the network. You should now be well aware of the error messages that will be displayed to people when your launching MiTM attacks against HTTPS websites.

I recommend infecting locally instead of globally. Targeting locally gives you an upper hand as you don't need to send your malware across the Internet for it to be analyzed and detected by AV. On top of that you can use local issues or common knowledge to your area to assist when developing your attack page to help social engineer the target(s).

If your HTML skills are shit then hopefully you're brushing up on those skills and plotting your MiTM attacks you plan on launching. Remember, the more effort you put into making everything look professional the better results you'll have!

In the next course ACT III will consist of how to infect specific targets with a malicious Microsoft Word document like I talked about in my example in the end of this chapter. ACT III will teach you how to create and develop malicious Word documents in order to infect your target(s). These techniques are good when you only have an e-mail of the target to work with and you're wanting to infect them with your RAT, ransomware, malware, etc. Are you after a specific company? Well then e-mail them your resume.doc and take control over them! Are you after a specific person? Time to reach out and e-mail them mesohorny.doc

From here moving forward in the next upcoming courses released at HackTown I want to get you into the mindset of becoming your own Advanced Persistent Threat (APT) when targeting anyone or anything. If you're following the North Korean, Iranian, or Russian government hackers then you should be familiar with some of their tradecraft. We'll take a look at nation state attacks and copy them for our own needs with tools already released. Think about that for a second. If other countries are targeting HUGE organizations with these types of tactics and are successfully compromising them what could you do if you followed their lead? Hmm? Think about it. You'll begin to realize that focusing your efforts towards smaller targets of interest will fuel your own wants and desires!

Learn that and more in ACT III!

Funshine

Board footer