Best approach for a site with no SSL
Hm... don't see what the absence of the SSL layer has to do with getting creds for it, it just means your http traffic is not encrypted and the site doesn't use any sort of certificate. Well, unless you're talking about user creds...

If you are looking for USER credentials, like their customer accounts, you should consider setting up a man in the middle attack via corrupted DNS caches. Due to the lack of SSL, you can easily request & resend the pages and requests, reading all of them and getting your hands on usernames and passwords. It won't make any difference to the end user, since they only get security alerts for https sites with faulty certificates.
With that approach, you might only get the hashed user creds so in order to login yourself, you would need to edit your own http requests for the site, which takes additional capturing efforts. I recommend using either burpsuite or tcpdump for it, as both of them are quite handy for copypasting http stuff.

Otherwise, sure, XSS and SQLI can do the trick too, if you know how to do it.

If you are after the website admin's creds, you could consider using some http webserver exploit, perhaps the site is missing a few patches since the admin was too cheap to setup ssl? Sometimes you can even XSS with php instead of js, which allows you to open a remote shell on the server.

Messages In This Thread
RE: Best approach for a site with no SSL - by serpent - 12-31-2020, 03:42 PM
RE: Best approach for a site with no SSL - by 9ys - 01-02-2021, 01:19 PM
RE: Best approach for a site with no SSL - by 9ys - 01-02-2021, 01:44 PM

