Hijacking KeePass password manager
If you have ever worked with network engineers or system administrators who work on multiple devices, then you have probably come across a password manager, simply because remembering each password is impossible for them. Usually, they use a password manager to securely store device credentials.
In this section, we will use a very common cross-platform software called KeePass and we will see how we can hijack passwords with the help of this software. You can download and install the software from https://keepass.info/download.html. After installing:
- Create a
NewDatabase
by clicking on theNew
icon. - Define
Master password
and click onOK
.
- Next, click on
eMail
and create a new account or a new entry for thegmail
account by right-clicking and selecting theAdd Entry...
option.
- Now, let's create a new entry for the PayPal account. Click on
Homebanking
, then right-click and select theAdd Entry...
option.
- So, let's log in and see whether we can use the password...