Labs · Cyber Security
Lab: Send the Same Practice Login over HTTP and HTTPS, Capture Both in Wireshark, and See Why TLS Matters
Course: Cyber Security · Chapter 24: Traffic Sniffing and Analysis
Chapter 24 explains traffic sniffing; this lab captures only your own traffic to show exactly what HTTPS protects.
Chala mitrano! People say "always use HTTPS", but why? Today we see it with our own eyes. We send the same fake username and password twice, once without encryption and once with it, and look at the packets. One will be readable like a postcard, the other like a sealed envelope. Bagha tar!
चला मित्रांनो! लोक म्हणतात "नेहमी HTTPS वापरा", पण का? आज आपण स्वतःच्या डोळ्यांनी बघणार. आपण तेच fake username आणि password दोनदा पाठवणार, एकदा encryption शिवाय आणि एकदा encryption सोबत, आणि packets बघणार. एक postcard सारखं वाचता येईल, दुसरं बंद पाकिटासारखं. बघा तर!
चलो दोस्तों! लोग कहते हैं "हमेशा HTTPS इस्तेमाल करो", पर क्यों? आज हम अपनी आँखों से देखेंगे। हम वही fake username और password दो बार भेजेंगे, एक बार encryption के बिना और एक बार encryption के साथ, और packets देखेंगे। एक postcard की तरह पढ़ा जा सकेगा, दूसरा बंद लिफ़ाफ़े की तरह। देखो तो!
Suppose we are…
Suppose we work in the IT security team at Café Coffee Day, which offers free Wi-Fi in its cafés. A manager asks: "If someone on the same café Wi-Fi watches the traffic, what can they see when a customer logs in?" We answer with a safe demo: we send a fake login from our own laptop to httpbin.org (a public service built for testing web requests) and capture only our own traffic in Wireshark.
Goal of this lab
By the end you will be able to:
- Capture your own HTTP request and read a password in plain text.
- Capture the same request over HTTPS and see only encrypted "Application Data".
- Explain what HTTPS still reveals (the website name) and what it hides.
What you need (all free)
- Your own laptop with Wireshark (Lab 3) and
curl(built into Windows 10+, macOS and Linux). - Internet access. 25–30 minutes.
Safety and ethics
Capture only your own traffic on your own laptop. Capturing other people's traffic on a shared Wi-Fi without permission is illegal. Use only the fake practice details below, never a real password.
Steps
- Open Wireshark and double-click your active adapter (Wi-Fi or Ethernet) to start capturing.
- In the display filter bar type
http.request.method == "POST"and press Enter. The list is empty for now. -
In a terminal, send a fake login over HTTP (on Windows use
curl.exe):curl -d "username=student01&password=Practice@123" http://httpbin.org/postWhat you should see in the terminal: a JSON reply that echoes
"password": "Practice@123"in theformsection. -
Back in Wireshark, one
POST /post HTTP/1.1line appears. Right-click it → Follow → HTTP Stream.What you should see: the full request in red text, including
username=student01&password=Practice@123. Anyone able to watch this network path could read it. -
Close the stream window. Now send the same login over HTTPS:
curl -d "username=student01&password=Practice@123" https://httpbin.org/post -
Change the display filter to
tlsand press Enter.What you should see:
Client Hello,Server Hello, then manyApplication Datalines. Nothing says POST and no password is visible. -
Click the Client Hello line. In the middle pane expand Transport Layer Security → Handshake Protocol → Extension: server_name.
What you should see:
Server Name: httpbin.org. HTTPS hides the content, but the website name is still visible. -
Right-click an Application Data line → Follow → TLS Stream. You see only scrambled bytes.
- Stop the capture (red square). Write a 3-line answer to the manager: what HTTP exposes, what HTTPS hides, what HTTPS still shows.
Ravindra Bagale's Tip
This is why browsers show "Not secure" for HTTP pages with a password box, and why your own site must redirect HTTP to HTTPS (Lab 13). And on public Wi-Fi, a padlock is the minimum, not the maximum. Mobile data or a trusted network is better for banking.
Ravindra Bagale's Tip – मराठी
म्हणूनच password box असलेल्या HTTP pages ला browser "Not secure" दाखवतो, आणि तुमच्या स्वतःच्या site ने HTTP ला HTTPS वर redirect करायलाच हवं (Lab 13). आणि public Wi-Fi वर padlock हे किमान आहे, कमाल नाही. Banking साठी mobile data किंवा trusted network जास्त चांगलं.
Ravindra Bagale's Tip – हिंदी
इसीलिए password box वाले HTTP pages पर browser "Not secure" दिखाता है, और आपकी अपनी site को HTTP से HTTPS पर redirect करना ही चाहिए (Lab 13)। और public Wi-Fi पर padlock न्यूनतम है, अधिकतम नहीं। Banking के लिए mobile data या trusted network बेहतर है।
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Typing a real password in the test | A real secret is sent to a public test service | Use only Practice@123 |
| Capturing on the wrong adapter | No packets appear | Pick the adapter with the moving traffic graph |
Using curl in Windows PowerShell 5 |
curl there is a different command and the -d option fails |
Type curl.exe |
Filter http shows nothing for HTTPS |
HTTPS is not readable HTTP on the wire | Use the tls filter for HTTPS |
| Thinking HTTPS hides everything | The site name, IPs and timing are still visible | Remember Server Name (SNI) in step 7 |
Self-check checklist
0 of 5 done
Try-at-home challenge
Repeat the HTTP test with header -H "Authorization: Basic c3R1ZGVudDAxOlByYWN0aWNlQDEyMw==" added. Find it in Wireshark and decode it. Is Basic authentication over HTTP safe?
Check your answer
The header is visible in the HTTP stream. Base64 is encoding, not encryption: decoding it (for example with echo c3R1ZGVudDAxOlByYWN0aWNlQDEyMw== | base64 -d) gives student01:Practice@123. Basic authentication is only acceptable over HTTPS.
Samjla ka? HTTP is a postcard, HTTPS is a sealed envelope with the address still on it. Aata pudhe jaauya: Chapter 25 secures the Wi-Fi itself.