G+_Jason Perry Posted November 5, 2017 Share Posted November 5, 2017 The more https becomes popular the more I need to find a product like shark tap that will act as a middle man. Anyone have suggestions? Link to comment Share on other sites More sharing options...
G+_Black Merc Posted November 6, 2017 Share Posted November 6, 2017 As long as you stay under gigabit... Diy build! Link to comment Share on other sites More sharing options...
G+_Jason Perry Posted November 6, 2017 Author Share Posted November 6, 2017 I have thought about it. My issue with that is it has to work. I don't have enough experience with encryption. Wireshark no problem, decrypting the traffic and then reencrypting the traffic is the part that is making me want to look for a prepackaged solution like shark tap. Link to comment Share on other sites More sharing options...
G+_Black Merc Posted November 6, 2017 Share Posted November 6, 2017 Raspberry with two nic? Mini pc with two nic? Both could work. Also hak5 lan turtle... Link to comment Share on other sites More sharing options...
G+_Ben Reese Posted November 7, 2017 Share Posted November 7, 2017 Yeah, intercepting the traffic isn't a problem. Decrypting all TLS traffic, inspecting, and repackaging with your own certs takes a bit more more. I've got no suggestions, but good luck! Link to comment Share on other sites More sharing options...
G+_Jason Perry Posted November 7, 2017 Author Share Posted November 7, 2017 I really don't think I am going to find what I want. Want I really want is a version of shark tap that will decrypt the traffic. Link to comment Share on other sites More sharing options...
G+_Black Merc Posted November 7, 2017 Share Posted November 7, 2017 Jason Perry shark tap is just a tap (an agragated tap). That's all it does. The smarts is in the device that you attach to the monitor port(rj-45). Link to comment Share on other sites More sharing options...
G+_Jason Perry Posted November 7, 2017 Author Share Posted November 7, 2017 Black Merc here is the question then how do you decrypt, inspect, and repackage without causing issues on your network? If I am using shark tap I guess I don't need to repackage but I feel like doing the decryption on the device attached to the monitoring port would be impossible. Link to comment Share on other sites More sharing options...
G+_David Wiggins Posted November 7, 2017 Share Posted November 7, 2017 If you have a managed switch, you could mirror traffic (just don't try to do more than one at a time, it can be a problem). As Ben Reese? said decrypt and repackage can be tricky. I've been playing with invisible proxy with SSL spoofing on pfS, and it's not exactly a walk in the park. With an invisible proxy, you could save the traffic until later, and use your proxy key to decrypt at leisure, or in real-time. This method requires control over either the gateway or the client devices. PAC and WPAD can be used for automatic proxy, but isn't always a good idea. Link to comment Share on other sites More sharing options...
G+_Dan Hockey Posted November 9, 2017 Share Posted November 9, 2017 Would this work hakshop.com - Packet Squirrel Link to comment Share on other sites More sharing options...
G+_Jason Perry Posted November 9, 2017 Author Share Posted November 9, 2017 Haven't looked at it yet. It is a new product. From what I have seen so far, or how I understand it is, your packet capture is limited by the size of the USB drive you have in it, when it is full its full. I don't think you can keep the most recent 'X' number of Gb of traffic. Link to comment Share on other sites More sharing options...
G+_Dan Hockey Posted November 11, 2017 Share Posted November 11, 2017 After watching Hak5 2309 I decided to get one. Link to comment Share on other sites More sharing options...
G+_Jason Perry Posted November 11, 2017 Author Share Posted November 11, 2017 After you play with it for awhile let me know how well works. Link to comment Share on other sites More sharing options...
Recommended Posts