One of your best friends has reason to believe that his girlfriend has been cheating on him. He thinks that she's been sending emails back and forth with this other guy, but he has no for sure proof. Now it's your turn to show him what a valuable friend you are!

Post by impulse_x on Fri May 17, 2013 5:57 am
When using wireshark, I'm supposed to filter by HTTP, but what if I'm originally logged on in HTTPS? Since all the
stuff are encrypted, I filter via ssl; but I can't read any of the encrypted stuff.

I've searched google for help on decrypting ssl handshakes and application data but that's completely above my
head and I don't see anyone saying anything about SSL on this thread.

And now, i don't even know how to go back to HTTP for

Any help appreciated.


Edit: I've completed this mission. Just forgot to post here as well as having forgotten how I figured it out. :(
Post by agentStag on Sat Mar 07, 2015 7:37 am
Hi guys, I have finally completed the mission.

I didn't use wireshark but the posts here suggest that it can be of help if you are stuck(do download it if you can, it will be useful for a person who visits this website).

Seems like most people are/were stuck at the c*****.*** file. The information given on that file on how should sections of it be removed was not necessary. So just think about how are variables separated on a URL and keep doing that until the end. Only worry about the first line, if you get that one right, it'll all be good.

The actual login isn't anything special so just get in.
A decompiler is needed and i used this one: It's all done online.

I hope this post helps(if i tell you more about that file, i'll spoil it).Contact me if you are still stuck. Good luck :geek:
