EnglishFrenchSpanish

OnWorks favicon

sslsniff - Online in the Cloud

Run sslsniff in OnWorks free hosting provider over Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

This is the command sslsniff that can be run in the OnWorks free hosting provider using one of our multiple free online workstations such as Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

PROGRAM:

NAME


sslsniff - SSL/TLS man-in-the-middle attack tool

SYNOPSIS


sslsniff [options]

DESCRIPTION


This manual page documents briefly the sslsniff command.

sslsniff is designed to create man-in-the-middle (MITM) attacks for SSL/TLS connections,
and dynamically generates certs for the domains that are being accessed on the fly. The
new certificates are constructed in a certificate chain that is signed by any certificate
that is provided.
sslsniff also supports other attacks like null-prefix or OCSP attacks to achieve silent
interceptions of connections when possible.

OPTIONS


Modes:

-a Authority mode. Specify a certificate that will act as a CA.

-t Targeted mode. Specify a directory full of certificates to target.

Required options:

-c <file|directory>
File containing CA cert/key (authority mode) or directory containing a collection
of certs/keys (targeted mode)

-s <port>
Port to listen on for SSL interception.

-w <file>
File to log to

Optional options:

-u <updateLocation>
Location of any Firefox XML update files.

-m <certificateChain>
Location of any intermediary certificates.

-h <port>
Port to listen on for HTTP interception (required for fingerprinting).

-f <ff,ie,safari,opera>
Only intercept requests from the specified browser(s).

-d Deny OCSP requests for our certificates.

-p Only log HTTP POSTs

-e <url>
Intercept Mozilla Addon Updates

-j <sha256>
The sha256sum value of the addon to inject

NOTES


sslsniff works only on the FORWARD traffic (not on INPUT or OUTPUT).

EXAMPLES


To intercept traffic on port 8443, start sslsniff on a local port:

sslsniff -a -c /usr/share/sslsniff/certs/wildcard -s 4433 -w /tmp/sslsniff.log

and redirect traffic to this port using the iptables nat table:

iptables -t nat -A PREROUTING -p tcp --destination-port 8443 -j REDIRECT --to-ports
4433

Use sslsniff online using onworks.net services


Free Servers & Workstations

Download Windows & Linux apps

  • 1
    Osu!
    Osu!
    Osu! is a simple rhythm game with a well
    thought out learning curve for players
    of all skill levels. One of the great
    aspects of Osu! is that it is
    community-dr...
    Download Osu!
  • 2
    LIBPNG: PNG reference library
    LIBPNG: PNG reference library
    Reference library for supporting the
    Portable Network Graphics (PNG) format.
    Audience: Developers. Programming
    Language: C. This is an application that
    can also...
    Download LIBPNG: PNG reference library
  • 3
    Metal detector based on  RP2040
    Metal detector based on RP2040
    Based on Raspberry Pi Pico board, this
    metal detector is included in pulse
    induction metal detectors category, with
    well known advantages and disadvantages.
    RP...
    Download Metal detector based on RP2040
  • 4
    PAC Manager
    PAC Manager
    PAC is a Perl/GTK replacement for
    SecureCRT/Putty/etc (linux
    ssh/telnet/... gui)... It provides a GUI
    to configure connections: users,
    passwords, EXPECT regula...
    Download PAC Manager
  • 5
    GeoServer
    GeoServer
    GeoServer is an open-source software
    server written in Java that allows users
    to share and edit geospatial data.
    Designed for interoperability, it
    publishes da...
    Download GeoServer
  • 6
    Firefly III
    Firefly III
    A free and open-source personal finance
    manager. Firefly III features a
    double-entry bookkeeping system. You can
    quickly enter and organize your
    transactions i...
    Download Firefly III
  • More »

Linux commands

Ad