BetterCap – Modular, Portable MiTM Framework

The New Acunetix V12 Engine


BetterCAP is a powerful, modular, portable MiTM framework that allows you to perform various types of Man-In-The-Middle attacks against the network. It can also help to manipulate HTTP and HTTPS traffic in real-time and much more.

BetterCap - Modular, Portable MiTM Framework


BetterCap has some pretty impressive Spoofing abilities with multiple host discovery (just launch the tool and it will start discovery), ARP spoofing, DNS spoofing and ICMP doubledirect spoofing.

The other tool similar to this would be: MITMf – Man-In-The-Middle Attack Framework and specfically for SSL you have sslsniff v0.7 – SSL Man-In-The-Middle (MITM) Tool.

BetterCap MiTM Features

Some of the main features include:

  • Full and half duplex ARP spoofing.
  • The first real ICMP DoubleDirect spoofing implementation.
  • Configurable DNS spoofing.
  • Realtime and completely automatized host discovery.
  • Realtime credentials harvesting for protocols such as HTTP(S) POSTed data, Basic and Digest Authentications, FTP, IRC, POP, IMAP, SMTP, NTLM ( HTTP, SMB, LDAP, etc ) and more.
  • Fully customizable network sniffer.
  • Modular HTTP and HTTPS transparent proxies with support for user plugins + builtin plugins to inject custom HTML code, JS or CSS files and URLs.
  • SSLStripping with HSTS bypass.
  • Builtin HTTP server.

Why BetterCap not Ettercap?

Ettercap still has some plus points like you can see connections and raw pcap stuff, but it’s not all relevant to everyone. Mostly it’s showing its’ age and BetterCap doesn’t have the below cons:


  • Ettercap was a great tool, but it’s old
  • Ettercap filters do not work most of the times
  • Ettercap filters are outdated
  • Ettercap filters are hard to implement due to the implementation language.
  • Ettercap is unstable on big networks (try host discovery on a network bigger than /24)
  • Ettercap is hard to extend or add modules to unless you’re a C/C++ developer.
  • Ettercap’s and MITMf’s ICMP spoofing is completely useless in 2016.
  • Ettercap does not provide a builtin and modular HTTP(S) transparent proxy.
  • Ettercap does not provide a smart and fully customizable credentials sniffer.

You can download BetterCap via the Ruby gem system so:

Then:

Kali Linux also has bettercap packaged, install it and all dependencies on the latest version of Kali using this:

Or read more here.

Posted in: Networking Hacking

, , , , , , ,


Latest Posts:


HTTP Security Considerations - An Introduction To HTTP Basics HTTP Security Considerations – An Introduction To HTTP Basics
HTTP is ubiquitous now with pretty much everything being powered by an API, a web application or some kind of cloud-based HTTP driven infrastructure. With that HTTP Security becomes paramount and to secure HTTP you have to understand it.
Cangibrina - Admin Dashboard Finder Tool Cangibrina – Admin Dashboard Finder Tool
Cangibrina is a Python-based multi platform admin dashboard finder tool which aims to obtain the location of website dashboards by using brute-force, wordlists etc.
Enumall - Subdomain Discovery Using Recon-ng & AltDNS Enumall – Subdomain Discovery Using Recon-ng & AltDNS
Enumall is a Python-based tool that helps you do subdomain discovery using only one command by combining the abilities of Recon-ng and AltDNS.
RidRelay - SMB Relay Attack For Username Enumeration RidRelay – SMB Relay Attack For Username Enumeration
RidRelay is a Python-based tool to enumerate usernames on a domain where you have no credentials by using a SMB Relay Attack with low privileges.
NetBScanner - NetBIOS Network Scanner NetBScanner – NetBIOS Network Scanner
NetBScanner is a NetBIOS network scanner tool that scans all computers in the IP addresses range you choose, using the NetBIOS protocol.
Metta - Information Security Adversarial Simulation Tool Metta – Information Security Adversarial Simulation Tool
Metta is an information security preparedness tool in Python to help with adversarial simulation and assess security defense preparation and alerts.


2 Responses to BetterCap – Modular, Portable MiTM Framework

  1. skriptkidd0r March 26, 2016 at 3:12 am #

    >Ettercap is hard to extend or add modules to unless you’re a C/C++ developer.

    ahahaha fucking script kiddies are afraid of learning a real language

    • Bluecoder March 28, 2016 at 3:16 am #

      I think its not just people are script kiddies its just that some of us are know python or ruby or java and well this is a good framework for cutting that time in adding modules by learning C++