NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Windows
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 05-07-2004   #16 (permalink)
arsham11
<-121->
 
arsham11's Avatar
 
Join Date: Mar 2004
Location: California
Posts: 29
Lightbulb final result...

After spending much time on this, the only realiable packet capture tools under windows platform seem to be commercial tools such as AiropeekNX! The other free tools are not optimized for 802.11 networks, but they can work just fine for IP based WLANs which DON'T use WEP. But they still do need the correct driver for hermes chipset which is only available with AiropeekNX. So what you can do is download the Airopeek Demo version and use the driver included with this tool.
Using this method all the WinPCap based tools work just fine!
I have included this topic in more detail in my thesis available at http://wifi.arsham.net .
__________________
<-arS-121-Ham->
arsham11 is offline   Reply With Quote
Old 05-26-2005   #17 (permalink)
Hiro_
Registered Member
 
Join Date: Apr 2005
Location: Gothenburg, Sweden
Posts: 16
Smile Sniffing a switched network (Windows)

Ok, so I've been playing around with ARP Poisoning a bit now but can't seem to find an app that suits me.

I installed EttercapNG (Ported to Windows) but found it hard to use. I found poisoning the victims easy with the user-friendly interface. Sniffing seemed to work fine, (but I couldn't find a way to make sure). Then I realized that EttercapNG actually uses it's own file-format(?) *.eci and *.ecp and not the common *.pcap-format. This sucked since then I was forced to use an text based tool (Etterlog) in DOS-mode to view the file and not being able to use the all powerful Ethereal :/

I Cain & Abel v2.69 worked much easier but seemed unstable. After poisoning my workstation and router I was able to do man-in-the-middle attacks from my laptop. I did a test run and tried to log on to my router from my workstation. I got to the logon-screen, tried to log on, sent the request. Cain & Able seemed to pick up the username and password just fine...then my Laptop (running Cain) blue dumped and my workstation never managed to bring up the html-site that the router should have generated. I guess that my router and my workstation still were poisoned since all traffic between them ceased to work. Only way around was to reboot both.

1. If I used and software to ARP poison my network, could I then use another sniffer software that normally just works in promiscious mode, say Ethereal, for man-in-the-middle sniffing?

2. What software would be appropriate?

3. Anybody got an Idea why my Cain session crashed?

4. Anybody know an app for viewing the EttercapNG capture?

Thanks // Hiro_
Hiro_ is offline   Reply With Quote
Old 05-26-2005   #18 (permalink)
Hiro_
Registered Member
 
Join Date: Apr 2005
Location: Gothenburg, Sweden
Posts: 16
Quote:
Originally Posted by semtecx
do an arp poisoning on all hosts in your network.
start an other sniffer like ethreal and sniff then the packages....

man in the middle......rox
What app would you use for ARP Poisoning then? I've been having some trouble with this (see above post)

Thanks // Hiro_
Hiro_ is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 01:10 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.