Forums: Arp Spoofing Get Packets - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Arp Spoofing Get Packets

#1 User is offline   Pro21 

  • Sergeant
  • Group: Members
  • Posts: 230
  • Joined: 12-February 04

Post icon  Posted 01 March 2004 - 01:37 PM



I post this thread to advance in this domain.
AT this moment i can get out packet in arp spoof but the most interesting is to get in packets.

Some explications on the sniff :

The goal is to get all packets from a network. But nowdays with the swith packets redirected at the good computer and not all computers. Before with hub it was possible to get all packets because hub it s as a RJ45 cable. But a switch build route tables for best performances on the lan and to guarantee more security.
Then the solution is to take an IP on the network ang sniff packets.

Computer 1 -------> Switch -------> Computer 2
_________________|
|
|
My computer

The goal is to be made pass for the computer 1 to get packets and after re-send packets at Computer 2.


An example : I am spoofing on a switched network :

ARP response send to 152.*.*.3 claiming to be 152.*.*.15
ARP response send to 152.*.*.2 claiming to be 152.*.*.66
ARP response send to 152.*.*.14 claiming to be 152.*.*.17
ARP response send to 152.*.*.44 claiming to be 152.*.*.11
ARP response send to 152.*.*.2 claiming to be 152.*.*.15

All packets redirected on my computer.
Then the manipulation is to sniff packets to get some password or informations.

T 152.*.*.107:3889 -> 152.*.*.36:110 [AP]
USER mblambet..

T 152.*.*.107:3889 -> 152.*.*36:110 [AP]
PASS 240191073..

T 152.*.*.107:3889 -> 152.*.*.36:110 [AP]
PASS 240191073..

I catched e-mail accounts.
But it s only Out packets. And if i try to connect me on a FTP on the lan, my connexion is invisible for the sniffer. But my principal goal is to get in packets.
But i don t see how to do this.

If you are an issue to help me :) it s the welcome :P

P.S : I am spoofing on a Windows computer :P WIndows RoX

0

#2 User is offline   Pro21 

  • Sergeant
  • Group: Members
  • Posts: 230
  • Joined: 12-February 04

Posted 02 March 2004 - 10:52 AM

sniff nobody have a solution :( sniff
0

#3 User is offline   niko 

  • Private First Class
  • Group: Members
  • Posts: 62
  • Joined: 07-October 03

Posted 04 March 2004 - 02:03 PM

Look up some more info on arp spoofing, maybe you don't have all your settings right.

You need to set your system up to route the packets (forward them) this might be why you only get out packets, since they never reach their destination, they never come back with anything..

-niko
0

#4 User is offline   technoboy 

  • Private First Class
  • Group: Members
  • Posts: 120
  • Joined: 10-January 04

Posted 04 March 2004 - 08:18 PM

and remember to be very careful on production network with arp spoofing and arp poissoning techniques, i know a few non-methodological pen-tester who lost there job after crashing the client network...
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users