In today's security-conscious world, most applications wisely use TLS to encrypt sensitive data in transit. However, not all environments are fully secured. Legacy systems, misconfigured services, or test applications launched without HTTPS can still result in the use of unencrypted protocols such as HTTP or SNMP. These gaps present a valuable opportunity for attackers: the chance to hunt for credentials in cleartext network traffic.

Wireshark

Wireshark is a well-known packet analyzer that comes pre-installed in nearly all penetration testing Linux distributions. It features a powerful filter engine that allows for efficient searching through both live and captured network traffic. Some basic but useful filters include:

Wireshark filter Description
ip.addr == 56.48.210.13 Filters packets with a specific IP address
tcp.port == 80 Filters packets by port (HTTP in this case).
http Filters for HTTP traffic.
dns Filters DNS traffic, which is useful to monitor domain name resolution.
tcp.flags.syn == 1 && tcp.flags.ack == 0 Filters SYN packets (used in TCP handshakes), useful for detecting scanning or connection attempts.
icmp Filters ICMP packets (used for Ping), which can be useful for reconnaissance or network issues.
http.request.method == "POST" Filters for HTTP POST requests. In the case that POST requests are sent over unencrypted HTTP, it may be the case that passwords or other sensitive information is contained within.
tcp.stream eq 53 Filters for a specific TCP stream. Helps track a conversation between two hosts.
eth.addr == 00:11:22:33:44:55 Filters packets from/to a specific MAC address.
ip.src == 192.168.24.3 && ip.dst == 56.48.210.3 Filters traffic between two specific IP addresses. Helps track communication between specific hosts.

In Wireshark, it's possible to locate packets that contain specific bytes or strings. One way to do this is by using a display filter such as http contains "passw". Alternatively, you can navigate to Edit > Find Packet and enter the desired search query manually. For example, you might search for packets containing the string "passw":

image.png

Pcredz ⚒️

Pcredz is a tool that can be used to extract credentials from live traffic or network packet captures. Specifically, it supports extracting the following information:

0xWALY@htb[/htb]$ ./Pcredz -f demo.pcapng -t -v