RE: Man in the middle attack help

From: David Ball (lostinvietnam@hotmail.com)
Date: Tue Mar 28 2006 - 03:50:19 EST


Just to mention that for MITM attacks arp cache poisoning is just one piece
of the puzzle. To pull off session hijacking, SSL or SSH MITM you will need
a variety of other tools some integrated into the proverbial swiss-army
knife toolsets like ettercap and dsniff and others as individual tools. For
example SSL MITM requires arpsoof(or some arp cache poisoning tool),
dnsspoof, webmitm, a sniffing tool like Ethereal and finally ssldump(to dump
passwords for example). SSH MITM requires arpspoof, dnsspoof and sshmitm.
You will also need to configure IP forwarding on the attacking machine. Not
sure that Session Hijacking is by strict definition a MITM attack but Hunt
and Juggernaut will help you here.

David.
>
>"Cafe pt-list" <cafe.ptlist@gmail.com>
>No Phone Info Available
>03/28/2006 01:43 PM
>
>To
>pen-test@securityfocus.com
>cc
>
>Subject
>Re: Man in the middle attack help
>
>Cain & Abel from oxit.it is a nice Windows tool for ARP Poison, MiTM,
>Sniffing and spoofing (IP/MAC).
>
>http://www.oxid.it/downloads/ca_setup.exe
>
>t+,
>Carlos Fernando Avila Gratz .
>
>
>
>On 3/25/06, Cedric Blancher <blancher@cartel-securite.fr > wrote:
> > Le samedi 25 mars 2006 à 16:14 +0100, Cedric Blancher a écrit :
> > > Look for dsniff package. There's a tool called macof that works on
> > > FreeBSD.
> >
> > And looking at your post subject, if you need some ARP cache poisoning
> > tool, you can have a look there:
> >
> > http://sid.rstack.org/arp-sk/
> >
> > There's a Windows version (winarp-sk) with a dedicated MiM tool
> > (winarp-mim), and there's FreeBSD port:
> >
> > http://www.freshports.org/net/arp-sk
> >
> >
> > --
> > http://sid.rstack.org/
> > PGP KeyID: 157E98EE FingerPrint:
>FA62226DA9E72FA8AECAA240008B480E157E98EE
> > >> Hi! I'm your friendly neighbourhood signature virus.
> > >> Copy me to your signature file and help me spread!
> >
> >
>------------------------------------------------------------------------------
> > This List Sponsored by: Cenzic
> >
> > Concerned about Web Application Security?
> > As attacks through web applications continue to rise, you need to
>proactively
> > protect your applications from hackers. Cenzic has the most
>comprehensive
> > solutions to meet your application security penetration testing and
> > vulnerability management needs. You have an option to go with a managed
> > service (Cenzic ClickToSecure) or an enterprise software (Cenzic
>Hailstorm).
> > Download FREE whitepaper on how a managed service can help you:
> > http://www.cenzic.com/forms/ec.php?pubid=10025
> > And, now for a limited time we can do a FREE audit for you to confirm
>your
> > results from other product. Contact us at request@cenzic.com
> >
>------------------------------------------------------------------------------
> >
> >
>

_________________________________________________________________
Learn English via Shopping Game, FREE!
http://www.linguaphonenet.com/BannerTrack.asp?EMSCode=MSN06-03ETFJ-0211E

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
As attacks through web applications continue to rise, you need to proactively
protect your applications from hackers. Cenzic has the most comprehensive
solutions to meet your application security penetration testing and
vulnerability management needs. You have an option to go with a managed
service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm).
Download FREE whitepaper on how a managed service can help you:
http://www.cenzic.com/forms/ec.php?pubid=10025
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com
------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:45 EDT