Any way to inject javascript codes when im MITM to any website victim visit WITHOUT downgrade HTTPS?

*disclaimer* i'm SKID who "play" for hobby with my lab and teach my self at slow pace so i know im SKID and not advanced hacker!

So like the title said, i success ARP spoofing and run MITM proxy and everything great,

Today when i downgrade to HTTP the browser alert the "victim" and put some barrier, i want just inject JavaScript code to any website/tab the user have, like hook.js of BEEF framework, and after that im the MITM and have stable hook to the victim i can go to the next step and try backdoor and whatever.

any way to inject JS code like that without downgrade or make the victim sus?

Thanks !

submitted by /u/itaypro2
[link] [comments]

from hacking: security in practice
