Decrypting TLS Browser Traffic with Wireshark (2015)
jimshaver.net
jimshaver.net
On a related note, to extract webmail passwords and more from memory, check out mimikittenz: https://github.com/putterpanda/mimikittenz . Basic usage: https://tinyapps.org/blog/windows/201607080700_extract_passw...
It can also be used to capture encrypted traffic on another device.
Fiddler MITM's creating a self-signed cert for each domain, which fails on apps that do cert pinning. I didn't get far enough to try but it also sounded like it didn't support smart cards for client certs in this mode either, asking for the private key in a file.
Just turning on the 'open dev tools for new windows' setting in Chrome is often enough to get what I need easily.
Thanks so much for the kind words, j_s. I'm afraid (or perhaps the word I'm looking for is "glad" ;-) that the Internet has passed tinyapps.org on by. After its fleeting 15 seconds of fame back in 2001 (thanks to a Slashdotting and tiny blurb in Wired), the site has mainly served as an irregular tech blog lo these many years.
Sorry that Fiddler did not prove efficacious. Thank you for the Chrome tip!
Also worth considering is Microsoft Message Analyzer, which used to be Network Monitor (NetMon). https://blogs.technet.microsoft.com/MessageAnalyzer/
Edit: I should add that this isn't an endorsement, just another option. I only included MMA as a side-note in my recent book. I focussed on Wireshark and Fiddler to keep things simple.
Full disclosure: it's my contribution.
This seems to imply it's impossible to decrypt the traffic due to the key exchange algorithm used, but isn't it actually an implementation issue of Wireshark? Yes, it can't decrypt old traffic (i.e. a pcap file) due to forward secrecy, but it should be possible to decrypt any on-the-fly traffic after knowing the private key by actively MITM-ing the connection
However, both sides obviously know the master secret, so if you can extract it from one of the clients then you can use that in wireshark to decrypt the application data packets. In wirshark preferences, this is called the pre-master-secret log filename.
As for acting as a MITM, Wireshark would have the same problem as anybody else in between the server and client: it doesn't have a valid certificate. Chrome would throw up a big scary warning and make it almost impossible to use the site.
The key is never transmitted (even in encrypted form), unlike with RSA. A good way of thinking about this is with a colour mixing analogy. I had a go at explaining this (with a Lego stormtrooper) here: https://unop.uk/understanding-encryption-and-key-exchange/
I'm a little wary of exporting SSLKEYLOGFILE into my systemwide environment. Everything can see it's set. Nothing stopping malware from grepping your disk for the string, sure, but seeing it in the environment is a practical guarantee the file it points to will successfully decrypt all HTTPS traffic. This feels a bit scary to me, since it's set-and-forget. (Or am I being too paranoid?)
Linux and macOS are easy to fix, just set the var in some obscure way you choose.
Windows is unfortunately less easy to fix; setting env vars per-process generally requires cmd.exe to flash on the screen, it seems :/
Also if anyone has used this to document everything Chrome sends back to the mother ship with its pinned certs.
And finally if it will be possible to implement something similar for IE and the rest of Windows (spyware/analytics) with Alex Ionescou's soon-to-be-released kernel driver interception framework.
Hey, hey, what do you know. First try with wireshark and I'm reading the ssl from the protected computer.
http://databaseblog.myname.nl/2014/07/decoding-encrypted-mys...
> Well my friends I’m here to tell you that there is an easier way! It turns out that Firefox and Chrome both support logging the symmetric session key used to encrypt TLS traffic to a file. You can then point Wireshark at said file and presto! decrypted TLS traffic.
The key only exists in Chrome and on the receiving webserver (and, if you follow the instructions, that file on disk, and then Wireshark). Once the key is discarded by all who hold it, the ability to decrypt the TLS session is lost.