Author Topic: Recommended way to harvest credentials ?  (Read 1267 times)

0 Members and 1 Guest are viewing this topic.

Offline blackrat

  • Serf
  • *
  • Posts: 21
  • Cookies: -5
    • View Profile
Recommended way to harvest credentials ?
« on: June 28, 2015, 09:28:29 am »
Hello i have a question. if one have got access to a router and can log into the config page. What attack would you guys recommend to steal login credentials ?

Offline dotszilla

  • Peasant
  • *
  • Posts: 68
  • Cookies: -61
  • ..you'll either LOVE me or HATE me..
    • View Profile
Re: Recommended way to harvest credentials ?
« Reply #1 on: June 28, 2015, 11:45:01 am »
its called Man In the middle attack do some research on it.. also you can portscan the computers on the network see what they running and try to exploit it.. KALI got a buncha stuff for MitM too,  incase youre not on linux..

BUT as far as the router config page goes only thing you can really do from there is get INFORMATION.. like how many devices on the network, their ip, MAC.. you can turn off the routers firewall if it has one... stuff like that...
« Last Edit: June 28, 2015, 11:51:11 am by dotszilla »
"The box said 'Requires Windows XP or better'. So I installed LINUX..."

Offline Trogdor

  • Peasant
  • *
  • Posts: 63
  • Cookies: -12
    • View Profile
Re: Recommended way to harvest credentials ?
« Reply #2 on: June 29, 2015, 07:23:37 am »
You could do a wordlist or brute force attack, but it will certainly show up in logs. You could also sniff the network for other credentials then apply them to the router page.  There usually isn't much use in attacking a router config page, as you can gather much more info using other tools and methods.

Offline nrael

  • Peasant
  • *
  • Posts: 66
  • Cookies: -7
    • View Profile
Re: Recommended way to harvest credentials ?
« Reply #3 on: July 03, 2015, 05:46:32 pm »
ARP attack. and then use wireshark or a specific tool to harvest passwords, list urls, steal cookies, change DNS servers.