Zanti 2 is a android application which is made up for network penetration testing.
For Demonstration :
Before install Zanti your Phone must be rooted .. In case your phone is not rooted search in the site you will find how to root android its very easy.
Step 2: After Opening the desirable victim i can see the open port and some other details
Its also shows the Nmap Scan Result
What Zanti 2 can do?
Scan the whole network
show alive host in the network
scan port through Nmap for port Scanning
Scan Service on each port and find vulnerability.
Perform Brute force attack
Perform Shellshock etc vulnerability
MITM: Man In The Middle Attack
Session Hijacking
SSL Striping
Sniffing packets
Replace image
Redirect URL and IP
Intercept and modified live download.
Scan the whole network
show alive host in the network
scan port through Nmap for port Scanning
Scan Service on each port and find vulnerability.
Perform Brute force attack
Perform Shellshock etc vulnerability
MITM: Man In The Middle Attack
Session Hijacking
SSL Striping
Sniffing packets
Replace image
Redirect URL and IP
Intercept and modified live download.
Disclaimer – Our tutorials are designed to aid aspiring pen testers/security enthusiasts in learning new skills, we only recommend that you test this tutorial on a system that belongs to YOU. We do not accept responsibility for anyone who thinks it’s a good idea to try to use this to attempt to hack systems that do not belong to you
For Demonstration :
Before install Zanti your Phone must be rooted .. In case your phone is not rooted search in the site you will find how to root android its very easy.
I used Zanti in my android device and Scan the network.
I choose the Mac OSx Machine which was my laptop.
After that start The MITM on and SSL strip to grab some packets and try to grab the password of that machine.
in the end i successfully travel the victim into http over https and grab the login credentials.
For demo kindly check the images which i posted in this post.
I choose the Mac OSx Machine which was my laptop.
After that start The MITM on and SSL strip to grab some packets and try to grab the password of that machine.
in the end i successfully travel the victim into http over https and grab the login credentials.
For demo kindly check the images which i posted in this post.
Step 1: Scan the whole wifi network.
After that Scan i get to know all the mobile and system connected to wifi network, its also scan the all ports as you can see in the above image.
I choose the 192.168.0.100
I choose the 192.168.0.100
Step 2: After Opening the desirable victim i can see the open port and some other details
1. Password Complexity audit: Its check and brute force the password ex: default password on the victim.
2. MITM: It Intercept the network packets via MITM attacks.
3. ShellShock : its check the vulnerability exist on the victim or not.
4. SSL Poodle : its check the target is it vulnerable for SSL Poodle attack or not.
Its also shows the Nmap Scan Result
In My demo i used MITM Attack on the Target.
Step 3: After Selecting MITM attack you will see many things you can do on target machine
In my case i switch “ON” the MITM which is on the Right-Top.
In next step i turned “ON” the SSL Strip.
As you can see i turned “ON” both things together by using Zanti2.apk in the MITM attack from my android device to hack the other phone or PC.
Step 4: After that I sniff the packets and SSL Striping working perfectly and strip hotmail in HTTP .
As you can see any site is strip into http and its ready to grab the password as soon as victim enter the login details.
No comments:
Post a Comment