Getting access to any accounts via session hijacking

BadB

Professional
Messages
2,563
Reaction score
2,770
Points
113
You will need:
1. Android Phone.
2. The Busy Box Library.
3. dSploit Program.
4. ROOT rights.

Instruction manual:
1. Install ROOT rights (I Recommend using KingRoot)
2. Install BusyBox
3. Install dSploit
4. Install the BusyBox library itself

467a2858aa59a51db0964.png

5. If you have a KingRoot program, it can block root for dSploit

So go to KingRoot and remove the ban.

96d3875254c502b347474.png

93e28dc994d1e0a32c123.png

896deb37f1a54293a8519.png

6. Run dSploit and see the following.

f8d08a7051f401ebe9a7b.png

All the things I've hidden are my MAC and IP addresses
  • All that has a server icon are devices connected to the Wi-Fi network.
  • But here it is difficult to determine whose traffic we need to intercept (you can guess), but we use the Network Utilities program (you can also do this in dSploit, but it only detects the operating system).
Everything is easy here, download Network Utilities and it can already determine the device model from its IP, with this information we go to dSploit and determine the victim.

Remark: since the author is located in Ukraine, to access the FB, he has to open a VPN, which in turn does not allow him to intercept the session. So the rest of the story will be based on the example of TELEGRAM.
(everything is the same as with Facebook, really no differences).

Telegram Account.
Victim logs in to Telegram.
At this time, we choose the victim.

8844a97be1276719cd322.png

Next, select MITM.

a0bf708001229eb0224b1.png

Next Session Hijacker.

9738d6802579b88aa02e8.png

Then click Start and intercept the session.

c5bfe2a6c9d95037a042c.png

Voila!

These actions can be repeated with almost any site, thereby gaining access to many accounts, since sessions can be stored and used later.
 
Top