I did all the configuration right. IPtables, port forwarding, ARPspoof, everything.
However, in the browser websites like Facebook and Twitter are still HTTPS.
What am I doing wrong?
Asked
Active
Viewed 436 times
4
2 Answers
4
Pick a softer target.
Update 1
So: Pick a target that doesn't use HSTS and/or pick a browser that doesn't care about HSTS.
StackzOfZtuff
- 18,093
- 1
- 52
- 86
0
I'm pretty sure it's worked for me in the past. If I recall correctly; you may need to de-authenticate your victim and wait for them to re-connect. On account of EAP/EAPOL, I do believe.
voices
- 1,779
- 8
- 23
- 36
And there is a way to bypass HSTS? not with SSLSTRIP.
– Antonio Oct 31 '15 at 13:27