This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

sniff out passwords?

0

so i'm very new to wireshark, and i'm currently trying to get into an account on 'moviestarplanet' i've been at it for hours now and nothing its working.

if anyone can help me out that would be VERY appreciated.

(fyi, i'm trying to get into an account that i own, and loss access to. AND YES, I TRIED THE "forgot your password?" THING BUT I'VE LOST THE EMAIL ACCOUNT I USED)

asked 11 Nov '16, 01:36

wankywentz's gravatar image

wankywentz
6114
accept rate: 0%


2 Answers:

3

answered 11 Nov '16, 01:46

Christian_R's gravatar image

Christian_R
1.8k2625
accept rate: 16%

2

First of all, looking at the "Contact" page of moviestarplanet (at least on the dutch version of the site), there are details on how to get back into moviestarplanet, even when you don't have access to your email anymore.

Then how to do it with wireshark (for future reference to people trying to retrieve lost passwords), there are two methods used to let you log in without providing credentials:

  1. Password stored in your browser. If your browser has the credentials, you don't need wireshark, as you can retrieve the login/password from the password manager in your browser.
  2. Persistent cookie. If the site uses a persistent cookie, the password is not stored, just a session token. So even when capturing the data, you will not see the username/password. If the site is using https, even the cookie is not visible as the traffic is encrypted.

So using wireshark to recover your own http username/password is really not the right road to take.

answered 11 Nov '16, 05:15

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%