hak4 / subterfuge

Automatically exported from code.google.com/p/subterfuge
GNU General Public License v3.0
0 stars 0 forks source link

Minor problems #96

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
What steps will reproduce the problem?
1. Running subterfuge.
2.
3.

What is the expected output? What do you see instead?

Subterfuge is running well but, I can't intercept data from tablets nor do they 
appear in the "network view" module consistently. Data can be intercepted form 
a smartphone if they use a browser to log in but not if they are already logged 
in with their apps.

So the question arises how can one knock a user off the site so that they log 
in again?  

What version of the product are you using? On what operating system?
Latest version 5.0.6 on kali Linux.

Please provide any additional information below.

Original issue reported on code.google.com by sonja.sa...@gmail.com on 26 Mar 2013 at 4:09

GoogleCodeExporter commented 8 years ago
Sufficient testing with tablets and mobile devices has not been completed yet. 
Any help with this would be appreciated. If a site does not work with 
Subterfuge, please add a comment in issue 56 
(http://code.google.com/p/subterfuge/issues/detail?id=56) with the device used, 
OS version, browser information, etc. so appropriate definitions can be created.

The option to "deauth" a user from a website to require them to log in again 
will be coming soon as an advanced setting. It will not be turned on by 
default. 

Original comment by topher.s...@gmail.com on 27 Mar 2013 at 1:10

GoogleCodeExporter commented 8 years ago
Hi there! Got some good news for you. I tried logging into facebook.com with my 
chrome browser on my android device (ver. 4.1.2) and I got through, same result 
with hotmail.com, yahoomail.com (but username wasn't shown "auth" was shown 
instead).

I also tried to log out of my accounts that I'm signed in with apps and log in 
again; I tried logging in with facebook it worked once but not again, facebook 
messenger didn't work, yahoo messenger didn't work, yahoo mail app didn't work, 
youtube app didn't work either nor does it work with through the browser. 

I think your "deauth" module would be of great help, hope you can get it out as 
soon as possible.

Original comment by sonja.sa...@gmail.com on 29 Mar 2013 at 2:34

GoogleCodeExporter commented 8 years ago
We're now actively working on extended support for credential harvesting 
against mobile devices.

Original comment by Mtoussain@gmail.com on 20 Oct 2013 at 5:14

GoogleCodeExporter commented 8 years ago

Original comment by topher.s...@gmail.com on 15 Dec 2013 at 5:39