Interceptor: A PowerShell SSL MITM Script

DerbyCon 4.0 - Family Rootz

Presented by: Casey Smith (@infosecsmith2)
Date: Saturday September 27, 2014
Time: 09:00 - 09:50
Location: Track 1

This talk will take you line by line through creating an SSL Man-In-The-Middle Powershell script. Modern malware often aims to steal web credentials and inject code into secure sessions. This script can be used to mimic that behavior, and expand your influence by collecting web credentials, or injecting “additional functionality” into a user’s web experience. In addition, you can mimic the behavior of applications such as Burp or Fiddler by extending or customizing this script. Topics covered include Dynamic CA and Signed Certificate Generation. PowerShell Sockets, Streams, Threads and SSL/TLS Interception and Tampering.

Casey Smith


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats