Monday, November 24, 2014

Steps:

  1.  First of all download and install wireshark. (Download Here)     Note: While Wireshark is getting installed, ensure that it installs the      Winpcap with it otherwise it won't work properly.
  2. Now go to the Capture button in the top menu of the Wireshark as shown below and select the interface( means your network card which can be Ethernet or WLAN).
  3. Now it will start capturing the packets through that Network card. What you have to do is just keep capturing the records for atleast 20 - 30 minutes for getting the best results. After 20 - 30 minutes, again go to capture and stop capturing the packets.
  4.  Now you need to filter your results, for this Go to the filter box and type FTP and SMTP one by one. Note: if you get records for FTP then hacker has used FTP server and if you didn't got FTP that means hacker has used SMTP, so give SMTP in Filter box.
  5. As you scroll down you will find the “FTP username” and “Password” for victims ftp account in case FTP server is used. And if hacker has used SMTP then you will find "email address" and its "password" that hacker has used to create keylogger.



1 comment:

Popular Posts

Recent Posts