3 ms·
The attacker more than likely just sniffed the credentials over the air. With the titles of the "hacking manuals" this guy didn't sound like a very sophisticat
by davis_m 15y ago
The attacker more than likely just sniffed the credentials over the air. With the titles of the "hacking manuals" this guy didn't sound like a very sophisticated attacker. This would have been before the large movement to HTTPS for logins, and a Yahoo login would have been easy to sniff. Even with HTTPS, SSLStrip, Ettercap, and arpspoof makes short work of HTTPS logins.
- laughinghan 15y agoShort work? As in, with a little Googling of these kinds of tools, anyone could be sniffing anyone else's HTTPS logins on a gigantic, campus-wide Wi-Fi network?