Sunday, May 4, 2025
Home Hacking Website Password hacking using WireShark

Website Password hacking using WireShark

by blackMORE
37 comments

Step 3: Analyze POST data for username and password

Now right click on that line and select Follow TCP Steam

Website Password hacking using WireShark - blackMORE Ops - 4

This will open a new Window that contains something like this:

HTTP/1.1 302 Found 
Date: Mon, 10 Nov 2014 23:52:21 GMT 
Server: Apache/2.2.15 (CentOS) 
X-Powered-By: PHP/5.3.3 
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" 
Set-Cookie: non=non; expires=Thu, 07-Nov-2024 23:52:21 GMT; path=/ 
Set-Cookie: password=e4b7c855be6e3d4307b8d6ba4cd4ab91; expires=Thu, 07-Nov-2024 23:52:21 GMT; path=/ 
Set-Cookie: scifuser=sampleuser; expires=Thu, 07-Nov-2024 23:52:21 GMT; path=/ 
Location: loggedin.php 
Content-Length: 0 
Connection: close 
Content-Type: text/html; charset=UTF-8

I’ve highlighted the user name and password field.

So in this case,

  1. username: sampleuser
  2. password: e4b7c855be6e3d4307b8d6ba4cd4ab91

But hang on, e4b7c855be6e3d4307b8d6ba4cd4ab91 can’t be a real password. It must be a hash value.

Note that some website’s doesn’t hash password’s at all even during sign on. For those, you’ve already got the username and password. In this case, let’s go bit far and identify this hash value

Step 4: Identify hash type

I will use hash-identifier to find out which type of hash is that. Open terminal and type in hash-identifier and paste the hash value. hash-identifier will give you possible matches.

See screenshot below:

Website Password hacking using WireShark - blackMORE Ops - 6

Now one thing for sure, we know it’s not a Domain Cached Credential. So it must be a MD5 hash value.

I can crack that using hashcat or cudahashcat. There’s an extensive guide on how to do that here.

You may also like

37 comments

daniele April 11, 2015 - 6:05 am

hi :)
As always many thanks for the interesting material in the mythical
blackmoreops.com

PS I did some tests ” refresher ” on some old and famous forum at http :
& After the filter http.request.method == " POST "
the credentials are in ” CLEAR ” in Base-Line text-data(wireshark)
ex: http://postimg.org/image/loiekr3jz/full/

thx-again :-)

Reply
blackMORE Ops April 11, 2015 - 12:55 pm

Cool.
I’ll add another post with some little tasks/challenges so that everyone can actually try few new things. Keep an eye on the website.

Reply
Nathan May 11, 2015 - 8:58 pm

Dude

Reply
zafar nawaz August 1, 2019 - 1:55 am

how to hack website usign wireshark on windows .. please tell or tell me this website admin password.. Thanks

Reply
Akyra Sevent April 13, 2015 - 6:34 pm

is that only capture your own network packet, right?
so, when we want to capture other computer packet, we must do arp poisoning, please correct me…

Reply
blackMORE Ops April 14, 2015 - 2:32 pm

Hi Akyra,
Correct. Or if you have access to the Gateway device(for example a router/proxy), you can just do it in there and all the HTTP password for the whole network will come up in Plaintext. Truly scary assuming that someone used the same password in a secured website and in a non-secured website. It’s very old hack but works till date.
My intention is to show how easily it can be done and people should be aware of it. Cheers,
-BMO

Reply
aarrsshh October 3, 2015 - 12:23 am

thanks blackmore ops
I have access to a person network … i know his router mac and from armitage i can access all his computers too but i m unable to find a way to wireshark his computers as u have jst said that its very easy to do so.. but due to my lack to knowledge i cannot do it..
when i start capturing data from wireshark it only shows the ip im using.. means its capturing only my data not his… would appreciate if u can explain how to capture his date and get passwords…

Reply
Afzal December 20, 2015 - 4:48 pm

it would be so helpful, f you could get me a tutorial on the method you just said.
pls help me out.

Reply
(*-*) November 18, 2016 - 10:06 pm

You can try promiscious mode in wireshark.

Reply
cpt-0bvious1 April 14, 2015 - 10:45 pm

You can also look for “data-text-lines” in the wireshark filter.
It gives all the packets were tis line is present.

Reply
Remik Pi April 18, 2015 - 5:05 am

Please note that sensitive data may be protected on the client-side when playing with plain-text connections e.g. with some JavaScript help. see http://tech.pro/tutorial/631/secure-authentication-without-ssl-using-javascript

Reply
herman May 12, 2015 - 4:52 pm

How do i know the desktop password over the network of my colleagues computer using wireshark.

Reply
Mia May 12, 2015 - 11:18 pm

Herman you can’t. Desktop password don’t drive over the network.

Reply
John May 28, 2015 - 4:12 am

I get an error when I type in the filter, basically saying it’s invalid.. any ideas?

Reply
ape July 9, 2015 - 2:17 am

http.request.method == “POST”

Reply
Manoj July 27, 2015 - 4:18 am

Remove double quotes and type it works

Reply
nferocious76 July 26, 2015 - 9:30 am

can we know the route where the traffic is being directed too? using wireshark? thank you

Reply
Ali Khan October 18, 2015 - 8:09 pm

Can I do all this on my android??
I want to hack my university DSL router username and password, so can anyone tell??

Reply
Gabi November 7, 2015 - 7:21 pm

hello friends,

My name is gabi and i really need some help with my newly installed Kali 2.0 Sana.

It actually worked for some couple of weeks and later started acting weird. The issue is this ;

I cannot browse the internet with either iceweasel or Firefox
I cannot use the terminal to ping any public internet address, even google dns server
BUT
I can use the TOR browser only to access the internet (WEIRD).

This is driving me crazy, just when i am preparing for my CEHv8 and other security certifications.

Please guys, the experts, help me out here. I will really appreciate any help.

Thanks

Gabi

Reply
Revizul November 13, 2015 - 8:53 am

look in the /etc folder for another folder named “Networkmanagement” , in this folder must be a config file, open it with a text editor and you will find the option somethink like “network” oder “networkcard managed” = false, just replace the “false” with “true” and save the config file, then you will be noticed that you are connected to the internet.

Reply
John February 9, 2016 - 3:51 am

Do these systems work with macs?

Reply
Deadpool March 19, 2016 - 2:45 am

hey bro i need help urgently i hacked my neighbours wifi but he know but don’t know who i am so i was thinking if i want to be remains anonymous how can i be or if any apps i am using hotspot shield elite. i need assurance he can never trace me …

Reply
sarita May 6, 2016 - 5:44 pm

can you please help me to hack wifi password

Reply
wymieniacz July 22, 2016 - 3:34 am

You should be alright… unless he has port mirroring. People usually don’t have it at home.

Reply
Gabe August 25, 2016 - 7:40 am

Hello. I am just wondering, if a wireless USB card is really needed? As for my computer, I have one built in. What would this be called in the Wireshark capture interfaces?

Reply
Helen August 30, 2016 - 2:50 pm

Do you need a professional to go to for all of your cyber/internet issues, i implore you to hire the best only so as to get your job completed without hassles.
For more info contact:
Darkwebssolutions on gmail or text +9193076946

Reply
jack December 13, 2016 - 10:46 pm

can u help me to hack a website and get the username and password ~
if can pls email to me
[email protected]

Reply
Yardstick December 23, 2016 - 3:59 pm

Please assist with retrieving the data website below.

Reply
Bismah anis February 4, 2017 - 8:51 pm

Does he charge money over it ?

Reply
Justin April 27, 2017 - 4:46 am

Will this only work if the victim uses an http link or will it still work if they use https and the website has an http version?

Reply
sandip February 7, 2018 - 9:03 pm

any alternate tool to hack website?

Reply
Richy July 1, 2018 - 12:44 am

contact dennixrichison@gmail. com for hacking services

Reply

Leave your solution or comment to help others.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

About Us

Lorem ipsum dolor sit amet, consect etur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis..

Feature Posts

Newsletter