Decrypting TLS , Capturing USB , Keyloggers, and Network Graphing

Jessey Bullock · 2017

This chapter walks through how to decrypt SSL/TLS. Encrypted traffic provides little insight into the data, apart from routing information, so this task can be useful for inspecting suspect activity. Next, the chapter focuses on sniffing USB traffic. It shows how users can use Wireshark to decrypt SSL/TLS-encrypted traffic. The session keys needed for decryption from the browser by setting the SSLKEYLOGFILE environment variable, and then feeding the resulting file to Wireshark are explained. With a solid understanding of how to capture USB packets, the chapter builds a simple keylogger using TShark, the TShark-based key sniffer. Finally, the chapter explains how to import the Graphviz Lua graphing library to help users visualize the network. Using the Graphviz library, an SVG file is created that contains all the network hosts, as well as the corresponding connections. The file allows users to quickly get an idea of the network topology without injecting any packets from the system.

Read the paper · More papers on PaperTik