From 87971d95868638f038327e618307dd51deaa3ebb Mon Sep 17 00:00:00 2001 From: byt3bl33d3r Date: Fri, 18 Jul 2014 13:21:48 +0200 Subject: [PATCH] now stripping hsts requests from headers --- plugins/JavaPwn.py | 3 --- sslstrip/ClientRequest.py | 2 ++ 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/plugins/JavaPwn.py b/plugins/JavaPwn.py index 18d7a16..1429021 100644 --- a/plugins/JavaPwn.py +++ b/plugins/JavaPwn.py @@ -1,6 +1,3 @@ -# -# Work in progress -# from plugins.plugin import Plugin from plugins.BrowserProfiler import BrowserProfiler from time import sleep diff --git a/sslstrip/ClientRequest.py b/sslstrip/ClientRequest.py index 5dfad7f..6c2281c 100644 --- a/sslstrip/ClientRequest.py +++ b/sslstrip/ClientRequest.py @@ -55,9 +55,11 @@ class ClientRequest(Request): if 'accept-encoding' in headers: headers['accept-encoding'] == 'identity' + logging.debug("zapped encoding") if 'Strict-Transport-Security' in headers: #kill new hsts requests del headers['Strict-Transport-Security'] + logging.debug("zapped a HSTS request") if 'if-modified-since' in headers: del headers['if-modified-since']