Real-time network traffic analysis tool to detect insecure credential transmission over HTTP.
NetSpecter CLI is a Linux-based cybersecurity tool that monitors live network traffic and identifies insecure transmission of credentials over plaintext protocols like HTTP and Telnet.
It uses packet inspection to detect sensitive data such as usernames and passwords being transmitted without encryption and alerts the user in real time.
- Real-time packet sniffing using Scapy
- Detects plaintext credential leaks (HTTP, Telnet)
- Supports multiple formats:
- Form data (
username=...&password=...) - JSON payloads
- Basic Auth headers
- URL Query parameters
- Multipart form data
- Form data (
- Optimized detection using fast byte-level pre-filtering
- Clean terminal alerts using Rich
- Includes test suite for the detection engine
- Python 3
- Scapy (packet capture and networking layers)
- Rich (CLI formatting and presentation)
git clone https://github.com/praneeth3696/NetSpecter.git
cd NetSpecter
pip install -r requirements.txt- Linux (Ubuntu / Kali recommended)
- Root privileges (
sudo) required for raw socket access - libpcap installed
Install libpcap if needed (Ubuntu/Debian):
sudo apt install libpcap-devStart scanning on the auto-detected default interface:
sudo python3 main.py scanOptional (specify an interface):
sudo python3 main.py scan --iface eth0Run this command in another terminal while NetSpecter is scanning to simulate an insecure login:
curl -X POST http://testphp.vulnweb.com/login.php -d "username=admin&password=1234"⚠️ INSECURE CREDENTIAL TRANSMISSION DETECTED
Source IP: 127.0.0.1
Destination IP: 127.0.0.1
Detection Type: form
Username: admin
Password: 1234
Confidence: HIGH
Credentials are transmitted in plaintext and can be intercepted.
- Does NOT work on HTTPS (encrypted traffic).
- Does NOT perform full TCP stream reassembly (split-packet payloads may be missed).
- Limited support for compressed bodies (
gzip,br) or HTTP/2 traffic frames.
NetSpecter/
├── detectors/
│ ├── __init__.py
│ └── http_credential_detector.py
│
├── tests/
│ └── test_http_credential_detector.py
│
├── docs/
│ └── http_credential_module_audit.md
│
├── main.py
├── sniffer.py
├── detector_wrapper.py
├── formatter.py
│
├── requirements.txt
├── .gitignore
└── README.md
- Demonstrating the fundamental insecurity of HTTP vs HTTPS.
- Learning packet inspection, sniffing, and network protocols.
- Educational cybersecurity experiments.
- Debugging insecure legacy API implementations.
Warning This tool is intended for educational and authorized testing purposes only. Do NOT use this tool on networks or systems without proper authorization and permission.
Praneeth