Ettercap / ettercap

Ettercap Project
http://www.ettercap-project.org
GNU General Public License v2.0
2.36k stars 492 forks source link

Dns spoof your connection is not private #1136

Closed ra0943-VK3ACH closed 3 years ago

ra0943-VK3ACH commented 3 years ago

When using dns spoof and following this tutorial https://null-byte.wonderhowto.com/how-to/tutorial-dns-spoofing-0167796/ and I go to a spoofed website on the victim it shows your connection is not private. Other websites not listed in ettercap.dns are also displaying the same message. I know the tutorial is a bit out of date but all of the options are there and called the same thing. Please help me I'm new to Kali Linux and ethical hacking and I have no idea what is happening. Thanks in advance

koeppea commented 3 years ago

Without knowing much about your exact setup, I assume you try to redirect a victim that tries to browse a ligit and popular website like facebook.com, and present it with a custom web server.

Well there is much todays web browsers do to aviod this attack vector. Please read here for more background on this. The error message is just a result of an non-matching SSL handshake that the client expected. The fact that the victim faces such an error message proves that the DNS poisoning actually works. Hence I'm closing this, as it's not a issue with Ettercap.