I have the admin account on a wifi router that multiple devices are connected too. I was wondering if there was any surveillance or password's I could sniff? Is there anything interesting I can do?
use wireshark
>>59254392
You can literally read every single packet that goes through the router. Anything unencrypted is yours
This is why public wifi is dangerous
>>59254392
Are you the NSA?
>>59254392
iptables -j TEE target
redirects a copy of all traffic to your computer
There you can analyze it with Wireshark.
>>59254392
So wire shark is the way to go?
How power full would it be? Could I get the handshake key's for a website's login?
You need to setup your own gateway with which you can sniff the traffic. Then change the ip of the router to something else, change your sniffers LAN side ip to the old router ip. Change sniffers wan side to the new router ip. Change dhcp scope on the router to point gateway at your sniffer lan side ip. Now you're sniffing for both new and existing clients.
>>59254868
>You need to setup your own gateway with which you can sniff the traffic.
No.
>>59254673
>>59254392
Run your own dns server, replace dns servers in the router and then redirect the page u are interested in sniff the password. You need to use some "social engineering" toolkit i really don´t think that is an apropiate name for that tools but anyway...... or just use sslsttrip2 + MITMF
>>59255126
i forgot if u have acces to the router via telnet u can edit the iptables from there and redirect the traffic and do some interesting things
>>59254882
That's exactly how you do it, you setup a middle man machine and force all the traffic to route through it while you sniff it.
>>59255276
You can´t just sniff a password in https....plain text password sure.....but https ? Without the RSA key or a dumped session key of the "attacked" browser
>>59255433
Yeah you're not going to sniff https or unless you also do ssl cert man in the middle. If you have control of the clients then you can install your own root ssl cert and then you can sniff everything