4

I did all the configuration right. IPtables, port forwarding, ARPspoof, everything.
However, in the browser websites like Facebook and Twitter are still HTTPS.
What am I doing wrong?

voices
  • 1,779
  • 8
  • 23
  • 36
Antonio
  • 145
  • 5

2 Answers2

4

Pick a softer target.

Update 1

So: Pick a target that doesn't use HSTS and/or pick a browser that doesn't care about HSTS.

StackzOfZtuff
  • 18,093
  • 1
  • 52
  • 86
0

I'm pretty sure it's worked for me in the past. If I recall correctly; you may need to de-authenticate your victim and wait for them to re-connect. On account of EAP/EAPOL, I do believe.

voices
  • 1,779
  • 8
  • 23
  • 36