Network Security & Cryptography Discuss f.ex. arp spoofing and hashes here.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 11th November 2008, 16:05
TheXero's Avatar
WiFi guru
 
Join Date: Sep 2008
Location: United Kingdom
Posts: 410
Rep Power: 12
Reputation: 219
TheXero has made his way up the systemTheXero has made his way up the systemTheXero has made his way up the system
eavesdropping/MITM

hi

me and some other students had a security adminstrator from our college network give us a lesson on security 2day

he used something along with wireshark to collect every packet that was running from my computer but also coming in

he wouldn't tell us what he did, but he did say that he didn't know my mac address

does anyone have any idea what this software could be?

cheers
__________________
OSWP Certified

Reply With Quote
  #2  
Old 11th November 2008, 18:25
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,424
Blog Entries: 36
Rep Power: 10
Reputation: 200
MaXe has made his way up the systemMaXe has made his way up the systemMaXe has made his way up the system
Re: eavesdropping/MITM

Download and use Ettercap-ng (works best on Linux)..

It's called MITM (Man/Monkey in the Middle) which you can perform
on LAN's, his method weren't probably as good as one i would have
done which would have included me being able to see everything
going on, on the desired LAN network.

Ettercap-ng -> CTRL-S -> MITM -> Tick some Arp thing -> Start / Listen
and you're all going, or you can just google Arp Spoofing or MITM attack :)


~ MaXe
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
  #3  
Old 11th November 2008, 22:09
TheXero's Avatar
WiFi guru
 
Join Date: Sep 2008
Location: United Kingdom
Posts: 410
Rep Power: 12
Reputation: 219
TheXero has made his way up the systemTheXero has made his way up the systemTheXero has made his way up the system
Re: eavesdropping/MITM

nice

when i get my (recently) spare pc up and working, i'll probably use cain and abel, or dual boot with ubuntu and run ettercap

cheers for the help maxe
__________________
OSWP Certified

Reply With Quote
  #4  
Old 11th November 2008, 22:16
Drathnar's Avatar
 
Join Date: Jul 2008
Posts: 406
Blog Entries: 1
Rep Power: 12
Reputation: 172
Drathnar has made his way up the systemDrathnar has made his way up the system
Re: eavesdropping/MITM

Arp Poisoning/MiTM Attack

See above :P
__________________
Drathnar
Director of Information Systems Security -- TSC Corp.
Owner Black Panther Consulting -- ISS Consulting

Reply With Quote
  #5  
Old 12th November 2008, 09:46
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,424
Blog Entries: 36
Rep Power: 10
Reputation: 200
MaXe has made his way up the systemMaXe has made his way up the systemMaXe has made his way up the system
Re: eavesdropping/MITM

It should work, though there's a GUI for ettercap-ng as well if you want to use that :)

To run it straight from console or the run-bar on linux, enter this: ettercap -G , in case
you don't have root privileges, issue this command: sudo ettercap -G ;)

Thanks for the guide Drathnar, i've given you rep for it as you can see :P


~ MaXe
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
  #6  
Old 27th February 2010, 17:47
Zero Cold's Avatar
 
Join Date: Dec 2009
Location: United Kingdom
Posts: 111
Rep Power: 4
Reputation: 91
Zero Cold will become a Token soon
Re: eavesdropping/MITM

with mitim attacks if u want to gather passwords i have mixed ettercap with ssl sniff to gather msn passwords etc as the old filter im ettercap will not bypass ssl authentication
__________________
Check Out My Site http://zero.intern0t.net/
Reply With Quote
  #7  
Old 16th March 2010, 05:47
 
Join Date: Feb 2010
Location: Manila, Philippines
Posts: 73
Rep Power: 3
Reputation: 24
gruenfeld777 is on the way to become something
Re: eavesdropping/MITM

I am on a wireless ISP(broadcast/reciever routers) and my neighbors appear on the LAN.

I used Cain and I was able to eavesdrop on some VOIP sessions. but it's irregular, sometimes you can't hear the other side it usually saves small wav files that sound like outer space.

Im trying to figure out how to recreate the long session logging.
Reply With Quote
  #8  
Old 22nd March 2010, 13:37
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,424
Blog Entries: 36
Rep Power: 10
Reputation: 200
MaXe has made his way up the systemMaXe has made his way up the systemMaXe has made his way up the system
Re: eavesdropping/MITM

Still, it sounded pretty cool gruenfeld xD
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
  #9  
Old 25th March 2010, 17:34
 
Join Date: Feb 2010
Location: Manila, Philippines
Posts: 73
Rep Power: 3
Reputation: 24
gruenfeld777 is on the way to become something
Re: eavesdropping/MITM

hehe yep it was fun. btw, maxe im thinking of learning python going all in. what do you recommend. I suppose php (your master art) ?

my purpose is to learn profiling websites and boxes.

Im also interested about the idea of "bouncing" after rooting a box. like using the metasploit framework as a payload. i'm curious about how exactly this increases your evasion.
Reply With Quote
  #10  
Old 25th March 2010, 17:52
Norph's Avatar
 
Join Date: Oct 2009
Location: Denmark
Posts: 374
Rep Power: 6
Reputation: 78
Norph will become a Token soon
Re: eavesdropping/MITM

There are of course tools to do so, but if you think of making your own, consider the following:
Profiling websites requires knowledge of HTML, JS and the like
Profiling boxes requires knowledge of the different protocols and exploits and tools (a lot of attack vectors).
Bouncing requires knowledge about TCP/IP (more specific sockets.)

But as said, there's tools for all of the above. I'm in a hurry, so please correct me. :P
__________________
I asked God for a bike, but I know God doesn't work that way. So I stole a bike and asked for forgiveness.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Article] MITM: Man In The Middle chroniccommand Offensive Guides & Information 10 19th July 2010 10:42
[Guide] Arp Poisoning/MiTM Attack Drathnar Offensive Guides & Information 3 12th November 2008 09:44


All times are GMT +2. The time now is 17:38.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1