You have learned in the previous lab how you can get username and password information using Wireshark. By merely capturing enough packets, attackers can extract the username and password if the victim authenticates themselves in a public network especially into a website without an HTTPS connection. Once the password is hacked, an attacker can simply log into the victim’s email account or use that password to log in to their PayPal and drain their bank account. They can even change the password for the email. Attackers can use Wireshark to decrypt the frames with the victim’s password they already have.
In this lab you have learnt how to sniff network traffic and perform ARP poisoning, launching a man-in-the-middle attack and sniffing the network for the password. Analyze and document the results related to the lab exercise. Give your opinion on your target’s security posture and “exposure” through public and free information.