Udemy

How to Bypass HTTPS

来自 Zaid Sabih 的免费视频教程
Ethical Hacker, Computer Scientist & CEO of zSecurity
评分:4.6,满分 5 分讲师评分
14 门课程
959608 名学生
How to Bypass HTTPS

讲座描述

All the programs we built so far only work with HTTP pages, this is because data sent over HTTPS is encrypted.

This lecture will fix this issue and teach you how to downgrade HTTPS to HTTP.

通过完整课程学习更多知识

Learn Python & Ethical Hacking From Scratch

Write 20+ hacking programs to learn hacking and programming at the same time | No prior knowledge required

24:49:25的随选视频 • 更新于 November 2025

180+ videos (25 hours) on Python programming & ethical hacking
Write over 20 hacking and security programs
Learn 2 topics at the same time - Python programming & Ethical Hacking
No programming, hacking or Linux knowledge required
Write programs in Python 2 and 3
Write cross platform programs that work on Windows, Apple Mac OS & Linux
Have a deep understanding on how computer systems work
Install hacking lab & needed software (on Windows, Apple Mac OS and Linux)
Start from 0 up to a high-intermediate level
Learn by example, by writing exciting programs
Model problems, design solutions & implement them using Python
Have a strong base & use the skills learned to write any program even if its not related to hacking
Understand what is Hacking, what is Programming, and why are they related
Design a testing lab to practice hacking & programming safely
Interact & use the Linux terminal
Understand what MAC address is & how to change it
Write a python program to change MAC address
Use Python modules and libraries
Understand Object Oriented Programming
Write object oriented programs
Model & design extendable programs
Write a program to discover devices connected to the same network
Read, analyse & manipulate network packets
Understand & interact with different network layers such as ARP, DNS, HTTP ....etc
Write a program to redirect the flow of packets in a network (ARP spoofer)
Write a packet sniffer to filter interesting data such as usernames and passwords
Write a program to redirect DNS requests (DNS Spoofer)
Intercept and modify network packets on the fly
Write a program to replace downloads requested by any computer on the network
Analyse & modify HTTP requests and responses
Inject code in HTML pages loaded by computers on the same network
Downgrade HTTPS to HTTP
Write a program to detect ARP Spoofing attacks
Write payloads to download a file, execute command, download & execute, download execute & report .....etc
Use sockets to send data over TCP
Send data reliably over TCP
Write client-server programs
Write a backdoor that works on Windows, Apple Mac OS and Linux
Implement features in the backdoor such as file system access, upload and download files and persistence
Write a remote keylogger that can register all keystrikes and send them by Email
Interact with files using python (read, write & modify)
Convert python programs to binary executables that work on Windows, OS X and Linux
Convert malware to torjans that work and function like other file types like an image or a PDF
Bypass Anti-Virus Programs
Understand how websites work, the technologies used and how to test them for weaknesses
Send requests towebsites and analyse responses
Write a program that can discover hidden paths in websites
Write a program that can map websites and discover all links, subdomains, files and directories
Extract and submit forms using python
Run dictionary attacks and guess login information on login pages
Analyse HTML using Python
Interact with websites using Python
Write a program that can discover vulnerabilities in websites
简体中文 [自动]
现在就去 到目前为止, 我们学会了如何成为中间人。 一旦我们成为中间人, 我们就学会了如何读取所有发送的数据。 所以我们能够读取用户名、 密码、 网址、 图片或人们浏览的任何东西。 我们还能够修改这些数据, 因此, 我们能够在目标浏览器浏览网站时, 将JavaScript代码或任何类型的代码注入目标浏览器。 这也让我们可以取代下载, 并进行许多很酷的攻击。 到目前为止, 我们所做的一切都只对HTTP页面有效。 它之所以对HTTP起作用是因为正如我们在数据中看到的, HTTP是以纯文本发送的。 所以这是像我们这样的人类可以阅读和理解的文本。 这就是为什么当我们处于中间的时候, 我们能够阅读这段文字。 如果我们愿意, 我们可以随意修改这段文字。 现在, 这显然是一个问题, 这个问题在https中得到了修复。 所以, 正如你所知, 大多数网站这些天使用HTTPS和所有好的网站。 著名网站使用HTTPS。 原因, 就像我说的, 因为它是HTTP的一个更安全的版本。 基本上, 它的工作方式是保持HTTP的实现完全相同。 因此, 所有标头以及数据发送的所有方式都保持不变。 所以HTTP没有被修改, 但是它在http上增加了一个额外的层, 这就是TSS的来源。 这是一个安全的HTTP协议, 这个额外的层将加密HTTP发送的明文数据。 因此, 如果一个人设法成为中间人, 他们将能够阅读这些数据。 但数据将是胡言乱语。 截取连接的人将无法读取该文件。 它只对用户和服务器有意义, 因为他们都有密钥, 并且能够解密加密的数据。 让我们举一个例子来说明这是什么样子的。 一般来说, 当我们使用阿普欺骗或任何其他方法成为中间人时, 我们知道, 请求将流经黑客。 黑客会将其转发到互联网或接入点, 然后是互联网, 然后响应将通过黑客的计算机流向受害者。 现在, 通常情况下, 如果一个人或一个用户试图访问一个网站, 比如说他们试图访问BBC。 他们会发送请求。 现在, 这个请求, 这个初始请求不会通过https发送, 除非用户在网站之前输入https。 我们知道大多数用户, 包括我自己, 我们不会真的输入https, 我们只是输入网站的名称。 所以如果他们想上BBC。 他们只会输入BBC。 com的网站。 因此, 初始请求将通过HTTP发送。 黑客是中间的人将收到这一点, 并转发到互联网。 英国广播公司。 另一方面, com会回应说, 嘿, 你为什么不通过https和我说话呢? 现在目标知道BBC可以通过https进行通信, 所以更加安全。 从现在开始, 他们将使用HTTPS与BBC通信。 因此, 在初始请求之后的所有请求都将通过https发送。 黑客将收到此信息, 并将其作为HTTPS再次转发到Internet。 服务器将使用https进行响应, 如您所见, 所有通信、 所有请求和响应都通过https发送。 现在, 就像我说的, HTTPS为HTTP协议增加了一个额外的加密层。 这将意味着我们通常在HTTP中读取的明文数据将被加密, 它对我们将没有用。 现在, 我们已经处于中间位置, 能够看到所有这些数据, 能够读取这些数据。 但这些数据将是胡言乱语。 它是不可读的, 因此我们将无法看到用户名、 密码、 URL或HTML代码, 因此我们将无法注入代码或修改这些数据包, 因为我们甚至无法在第一时间读取它们。 现在, 这对我们作为一个黑客来说真的很糟糕, 因为我们做了所有的艰苦工作, 试图成为中间人。 而一旦我们被夹在中间, 就无法利用这个非常好的位置了。 幸运的是, 有一个聪明的家伙叫Moxy, 他已经击败SSL很长一段时间了, 这个家伙想出的一个方法允许我们绕过HTTPS并将其降级为HTTP。 现在, 莫西发现的可不仅仅是这一击。 他还写了一个伟大的工具, 将为我们做这件事。 我们再看一下初始请求。 就像我们说的, 通常人们在请求网页时不会输入https, 所以他们会输入, 例如, BBC。 通信 这将通过黑客的计算机, 谁是谁已经是中间人, 也正在运行一个工具称为SQL剥离, 这是实现马克斯的攻击的工具。 现在, 该工具将看到这是一个HTTP请求, 因此它不会处理它。 这对我们黑客来说是件好事, 它只会把它转发到互联网上。 下一个, BBC。 com会回应说, 嘿, 你为什么不通过https和我交流呢? 现在, SSL strip将检测到这一点。 顺便说一句, 当我说BBC会说, 嘿, 你为什么不通过https和我交流呢? 这个过程实际上比这个要复杂一点, 但我只是想让它尽可能简单。 SSL strip将检测到服务器试图告诉目标通过https进行通信, 它将删除或剥离所有字段和所有数据。 这基本上就是说, 让我们将此连接升级为HTTPS连接。 因此, 响应将以HTTPS响应的形式出现, 但Sstl strip将剥离该响应, 只将看起来像正常HTTP响应的部分转发给受害者。 到目前为止, 受害者还不知道服务器可以通过https进行通信, 因此它将把下一个请求作为普通HTTP请求发送。 这里是SSL strip的智能之处, 因为它将跟踪所有发送HTTP响应的网站。 因此, 即使受害者在与BBC通信时发送HTTP请求。 SSL脚本知道BBC。 com喜欢通过https进行通信。 因此, 一旦它从受害者或目标获得HTTP请求, 它就会将该连接升级为HTTPS连接。 就BBC而言。 它告诉目标你应该通过HTTPS与我通信, 目标通过开始通过https通信来响应。 所以这对BBC来说是完美的。 和受害者。 对他们来说。 他们不认为BBC。 com可以通过https进行通信, 因为它们每次发送HTTP请求时, 都会得到HTTP响应。 所以他们不认为BBC可以通过https进行通信, 因为如果它可以, 那么它会对受害者说“通过https与我通信”。 现在这个配置是完美的, 因为我们。 因为黑客能够读取明文形式的请求和响应, 没有人知道我们在玩弄连接。 目标认为他们尝试访问的网站只支持HTTP, web服务器也很高兴, 因为它通过https与他们认为是他们的客户端进行通信, 但他们实际上与我们连接。 现在, 我们可以在这里, 当我们从互联网获得HTTP响应时, 我们实际上能够读取它们, 因为我们是发起HTTP请求的人。 因此, 您可以看到, HTTPS循环实际上只在我们和互联网或web服务器之间, 而不是在受害者和web服务器之间。 现在, Sstl strip将做的另一件事是, 当它加载一个网页时, 它实际上会将页面中的所有链接从HTTPS转换为普通的HTTP。 这样, 当SSL strip工作时, 所有HTTPS连接都将降级为HTTP。 现在, 由于连接将被降级为HTTP, 这意味着数据将以明文形式发送, 这意味着我们将能够读取和修改这些数据, 就像我们通常使用HTTP所做的那样。 现在有一个例外, 这整个规则, 这是网站使用HST的, 因为现在HTTPS是由Facebook, 贝宝和Gmail使用, 例如。 基本上, 其工作方式是目标受害者的浏览器提供一个硬编码的网站列表, 它应该只以https加载。 因此, 即使我们尝试了所有我们可以尝试的方法, 并试图将此连接降级为HTTP, 浏览器也会拒绝加载此页面, 因为它知道此页面必须通过https加载。 到目前为止, 还没有一种实用的方法可以绕过主机。 有过, 但后来修好了。 但一旦有新的方法可以绕过它, 我会尽快告诉你最新情况。