maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Applications (https://talk.maemo.org/forumdisplay.php?f=41)
-   -   [Tutorial] Pentesting Wireless Networks (https://talk.maemo.org/showthread.php?t=73572)

karam 2012-02-25 12:47

Re: [How To] Install Hacking Tools On N900
 
sry about that
fixing it now

seems that there was (chown) error as i moved them from my N900 directly from MyDocs

as for new hydra well i can't compile anything now, i don't have time nor the good environment to do so

StefanL 2012-02-25 16:01

Re: [How To] Install Hacking Tools On N900
 
1 Attachment(s)
Quote:

Originally Posted by karam (Post 1169553)
sry about that
fixing it now

seems that there was (chown) error as i moved them from my N900 directly from MyDocs

as for new hydra well i can't compile anything now, i don't have time nor the good environment to do so

Compiled version of hydra 7.2 attached. This one does not have support for the following services: postgres sapr3 firebird afp ncp ssh svn oracle mysql5 and regex.

safoo 2012-02-25 20:08

Re: [How To] Install Hacking Tools On N900
 
1 Attachment(s)
cannot complete it.. I encountered an error on Part 1.. stucked at step

"Now download karam.tar.gz from :
http://dl.dropbox.com/u/44965378/N900%20mods/karam.zip

Then put in MyDocs and :
-------
cd /home/user/MyDocs
tar -xzvf karam.tar.gz
-------
To have all needed files"

somebody help to complete this step by step..

karam 2012-02-25 22:18

Re: [How To] Install Hacking Tools On N900
 
@StefanL
thank you for compiling it


@i don't recommend using that method
i have uploaded most of the tools to extras-devel

//edit 1st post edited , thread subject changed

StefanL 2012-02-26 11:54

Re: [How To] Install Hacking Tools On N900
 
1 Attachment(s)
Quote:

Originally Posted by karam (Post 1169757)
@StefanL
thank you for compiling it

The attached version has some more modules enabled and also contains pw-inspector. Now the list of services not compiled in is: sapr3 firebird afp ncp ssh svn oracle. ;)

safoo 2012-02-26 18:47

Re: [Tutorial] Pentesting Wireless Networks
 
tell me if i have done it correctly or not..

BusyBox v1.10.2 (Debian 3:1.10.2.legal-1osso30+0m5) built-in shell (ash)
Enter 'help' for a list of built-in commands.

~ $ sudo gainroot
Root shell enabled


BusyBox v1.10.2 (Debian 3:1.10.2.legal-1osso30+0m5) built-in shell (ash)
Enter 'help' for a list of built-in commands.

/home/user #
/home/user # apt-get install nmap driftnet charon yamas wireshark tshark kismet cleven cowpatty
Reading package lists... Done
Building dependency tree
Reading state information... Done
nmap is already the newest version.
wireshark is already the newest version.
tshark is already the newest version.
kismet is already the newest version.
The following extra packages will be installed:
busybox-power dsniff ettercap ettercap-common libjpeg7
libnet0 libnet1 libssl0.9.7 macchanger mdk3 sslstrip
Suggested packages:
reaver wash
The following NEW packages will be installed:
busybox-power charon cleven cowpatty driftnet dsniff
ettercap ettercap-common libjpeg7 libnet0 libnet1
libssl0.9.7 macchanger mdk3 sslstrip yamas
0 upgraded, 16 newly installed, 0 to remove and 58 not upgraded.
Need to get 5557kB of archives.
After this operation, 12.0MB of additional disk space will be used.
Do you want to continue [Y/n]? Y
Get:1 http://repository.maemo.org fremantle/free mdk3 1.1 [48.5kB]
Get:2 http://repository.maemo.org fremantle/free charon 1.1 [1533kB]
Get:3 http://repository.maemo.org fremantle/free cowpatty 1.1 [15.5kB]
Get:4 http://repository.maemo.org fremantle/free libjpeg7 7-1.maemo5v1 [135kB]
Get:5 http://repository.maemo.org fremantle/free driftnet 1.2 [20.1kB]
Get:6 http://repository.maemo.org fremantle/free libnet0 1.0 [13.6kB]
Get:7 http://repository.maemo.org fremantle/free libssl0.9.7 1.0 [433kB]
Get:8 http://repository.maemo.org fremantle/free dsniff 1.2 [1879kB]
Get:9 http://repository.maemo.org fremantle/free libnet1 1.1.4-2maemo2 [56.7kB]
Get:10 http://repository.maemo.org fremantle/free ettercap-common 1:0.7.3-2maemo4 [310kB]
Get:11 http://repository.maemo.org fremantle/free ettercap 1:0.7.3-2maemo4 [188kB]
Get:12 http://repository.maemo.org fremantle/free sslstrip 0.9-0maemo1 [24.6kB]
Get:13 http://repository.maemo.org fremantle/free busybox-power 1.19.3power5 [517kB]
Get:14 http://repository.maemo.org fremantle-1.3/free macchanger 1.5.0-4 [90.2kB]
Get:15 http://repository.maemo.org fremantle-1.3/free cleven 2.4-8 [269kB]
Get:16 http://repository.maemo.org fremantle/free yamas 1.0.0-1 [23.1kB]
Fetched 5557kB in 54s (101kB/s)
Selecting previously deselected package mdk3.
(Reading database ... 32890 files and directories currently installed.)
Unpacking mdk3 (from .../archives/mdk3_1.1_armel.deb) ...
Selecting previously deselected package charon.
Unpacking charon (from .../archives/charon_1.1_armel.deb) ...
Selecting previously deselected package cowpatty.
Unpacking cowpatty (from .../cowpatty_1.1_armel.deb) ...
Selecting previously deselected package libjpeg7.
Unpacking libjpeg7 (from .../libjpeg7_7-1.maemo5v1_armel.deb) ...
Selecting previously deselected package driftnet.
Unpacking driftnet (from .../driftnet_1.2_armel.deb) ...
Selecting previously deselected package libnet0.
Unpacking libnet0 (from .../archives/libnet0_1.0_armel.deb) ...
Selecting previously deselected package libssl0.9.7.
Unpacking libssl0.9.7 (from .../libssl0.9.7_1.0_armel.deb) ...
Selecting previously deselected package dsniff.
Unpacking dsniff (from .../archives/dsniff_1.2_armel.deb) ...
Selecting previously deselected package libnet1.
Unpacking libnet1 (from .../libnet1_1.1.4-2maemo2_armel.deb) ...
Selecting previously deselected package ettercap-common.
Unpacking ettercap-common (from .../ettercap-common_1%3a0.7.3-2maemo4_armel.deb) ...
Selecting previously deselected package ettercap.
Unpacking ettercap (from .../ettercap_1%3a0.7.3-2maemo4_armel.deb) ...
Selecting previously deselected package sslstrip.
Unpacking sslstrip (from .../sslstrip_0.9-0maemo1_all.deb) ...
Selecting previously deselected package busybox-power.
Unpacking busybox-power (from .../busybox-power_1.19.3power5_armel.deb) ...
busybox-power: Maemo (N900) environment detected
Selecting previously deselected package macchanger.
Unpacking macchanger (from .../macchanger_1.5.0-4_armel.deb) ...
Selecting previously deselected package cleven.
Unpacking cleven (from .../cleven_2.4-8_armel.deb) ...
BEGIN preinstall@2.4-8: install
END preinstall@2.4-8: install
Selecting previously deselected package yamas.
Unpacking yamas (from .../yamas_1.0.0-1_armel.deb) ...
Setting up mdk3 (1.1) ...
Setting up charon (1.1) ...
Setting up cowpatty (1.1) ...
Setting up libjpeg7 (7-1.maemo5v1) ...
Setting up driftnet (1.2) ...
Setting up libnet0 (1.0) ...
Setting up libssl0.9.7 (1.0) ...
Setting up dsniff (1.2) ...
Setting up libnet1 (1.1.4-2maemo2) ...
Setting up ettercap-common (1:0.7.3-2maemo4) ...
Setting up ettercap (1:0.7.3-2maemo4) ...
Setting up sslstrip (0.9-0maemo1) ...
Setting up busybox-power (1.19.3power5) ...
Setting up macchanger (1.5.0-4) ...
Setting up cleven (2.4-8) ...
BEGIN postinstall@2.4-8: configure
Listing /opt/cleven/ ...
Compiling /opt/cleven/clevenCaptureUI.py ...
Compiling /opt/cleven/clevenDictionaryUI.py ...
Compiling /opt/cleven/clevenDriversUI.py ...
Compiling /opt/cleven/clevenKeysUI.py ...
Compiling /opt/cleven/clevenMain.py ...
Compiling /opt/cleven/clevenMainUI.py ...
Compiling /opt/cleven/clevenManageCapturedUI.py ...
Compiling /opt/cleven/clevenStartupUI.py ...
Listing /opt/cleven/compat-wireless ...
END postinstall@2.4-8: configure
Setting up yamas (1.0.0-1) ...
/home/user #

:)

Mohammed Muid 2012-02-26 19:27

Re: [Tutorial] Pentesting Wireless Networks
 
how to use driftnet? any tutorial? plz

StefanL 2012-02-27 15:05

Re: [Tutorial] Pentesting Wireless Networks
 
1 Attachment(s)
The attached version has one more module enabled (ssh) and also contains pw-inspector. Now the list of services not compiled in is: sapr3 firebird afp ncp svn oracle. ;).

Please test and provide some feed-back, since I am not actually using this; only compiled it since Karam's development system is borked.

Mohammed Muid 2012-02-27 15:44

Re: [Tutorial] Pentesting Wireless Networks
 
is der anyone who successfully used driftnet. can you please share how to use that. i am nt being able to get it work out. plzz anyone help

spuddy101 2012-02-27 16:56

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by StefanL (Post 1170608)
The attached version has one more module enabled (ssh) and also contains pw-inspector. Now the list of services not compiled in is: sapr3 firebird afp ncp svn oracle. ;).

Please test and provide some feed-back, since I am not actually using this; only compiled it since Karam's development system is borked.

HI ive tried hydra 7.2 i have a problem when i run hydra i get an error
saying:libssl1.so.1.0.0 cannot open shared object file no such file or directory can you help thanks

q6600 2012-02-27 18:56

Re: [Tutorial] Pentesting Wireless Networks
 
The second uploaded version of hydra 7.2 is not working ( like in the PM StefanL) i had the same error like spuddy101. I install back the first version uploaded by stefanl on post 201.

karam 2012-02-27 19:41

Re: [Tutorial] Pentesting Wireless Networks
 
hmm it seems it's grabbed by debian repository (binary or source)

if you have libss1 installed then do :

ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl1.so.1.0.0

not sure as i have hydra installed on easy-debian

StefanL 2012-02-27 23:22

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by karam (Post 1170847)
hmm it seems it's grabbed by debian repository (binary or source)

if you have libss1 installed then do :

ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl1.so.1.0.0

not sure as i have hydra installed on easy-debian

My N900 is my development environment so I do not have a fresh one to test the programs on; obviously on my set-up all the dependencies are satisfied since it compiled. :(

Try the following to fix missing dependencies
Code:

sudo apt-get install libssh libmysqlclient libpq libssl pkg-config libgtk2.0
Just try each of the packages after the install separately until you find the one that fixes the dependency. Report back here to let us know what works.

psychologe 2012-02-28 04:48

Re: [Tutorial] Pentesting Wireless Networks
 
hi StefanL,i download your attached on #207.
but it must install some lib.
when i execute below command,hydra can work.
1,apt-get install libidn11 libpq5 libssh2-1 libcrypt
2,ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl.so.1.0.0
3,ln -s /usr/lib/libssh2.so.1 /usr/lib/libssh.so.4
4,ln -s /usr/lib/libcrypto.so.0.9.8 /usr/lib/libcrypto.so.1.0.0

i used valid login/password pairs test it on My N900's sshd and telnet server.but hydra can't suggest valid !

Nokia-N900:~# hydra -l root -p qazwsx 127.0.0.1 ssh
Hydra v7.2 (c)2012 by van Hauser/THC & David Maciejak - for legal purposes only

Hydra (http://www.thc.org/thc-hydra) starting at 2012-02-28 12:47:21
[DATA] 1 task, 1 server, 1 login try (l:1/p:1), ~1 try per task
[DATA] attacking service ssh on port 22
hydra: symbol lookup error: hydra: undefined symbol: ssh_new
[STATUS] attack finished for 127.0.0.1 (waiting for children to finish)
1 of 1 target successfuly completed, 0 valid passwords found
Hydra (http://www.thc.org/thc-hydra) finished at 2012-02-28 12:47:21

Nokia-N900:~# hydra -l root -p qazwsx 127.0.0.1 telnet -vv
Hydra v7.2 (c)2012 by van Hauser/THC & David Maciejak - for legal purposes only

Hydra (http://www.thc.org/thc-hydra) starting at 2012-02-28 12:49:11
[WARNING] telnet is by its nature unreliable to analyze reliable, if possible better choose FTP or SSH if available
[VERBOSE] More tasks defined than login/pass pairs exist. Tasks reduced to 1.
[DATA] 1 task, 1 server, 1 login try (l:1/p:1), ~1 try per task
[DATA] attacking service telnet on port 23
[VERBOSE] Resolving addresses ... done
[STATUS] attack finished for 127.0.0.1 (waiting for children to finish)
1 of 1 target successfuly completed, 0 valid passwords found
Hydra (http://www.thc.org/thc-hydra) finished at 2012-02-28 12:49:11

q6600 2012-02-28 08:43

Re: [Tutorial] Pentesting Wireless Networks
 
2 Attachment(s)
sudo apt-get install libidn11

sudo apt-get install libssh libmysqlclient libpq libssl pkg-config libgtk2.0

ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl1.so.1.0.0

but still not working last hydra from post 207


i try
1,apt-get install libidn11 libpq5 libssh2-1 libcrypt
2,ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl.so.1.0.0
3,ln -s /usr/lib/libssh2.so.1 /usr/lib/libssh.so.4
4,ln -s /usr/lib/libcrypto.so.0.9.8 /usr/lib/libcrypto.so.1.0.0

still no luck

bharathkumarst 2012-02-28 15:32

Re: [Tutorial] Pentesting Wireless Networks
 
@karam
Great efforts are put by you!
I am new to pentesting. Can you help me how to use these pentesting tools? Any tutorials for usage? Any videos? Pl help.

bharathkumarst 2012-02-28 15:34

Re: [Tutorial] Pentesting Wireless Networks
 
I am a windows user...

StefanL 2012-02-28 22:19

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by q6600 (Post 1171267)
sudo apt-get install libidn11

sudo apt-get install libssh libmysqlclient libpq libssl pkg-config libgtk2.0

ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl1.so.1.0.0

but still not working last hydra from post 207


i try
1,apt-get install libidn11 libpq5 libssh2-1 libcrypt
2,ln -s /usr/lib/libss.so.1.0.0 /usr/lib/libssl.so.1.0.0
3,ln -s /usr/lib/libssh2.so.1 /usr/lib/libssh.so.4
4,ln -s /usr/lib/libcrypto.so.0.9.8 /usr/lib/libcrypto.so.1.0.0

still no luck

Ok, I need to change my development environment. I had compiled the openssl 1.0.0.e library from the website and was testing it on my device, but official maemo one is 0.9.8. Sorry about the f@ck up. Will post a new compiled version soon. For those who are interested run the following in x-term
Code:

ldd hydra
and you will see which libraries are compiled into it. libssl and libcrypto are there twice. Will post more specifics on the required dependencies with the next version as well.

q6600 2012-02-28 23:50

Re: [Tutorial] Pentesting Wireless Networks
 
1 Attachment(s)
Any help for you guys

StefanL 2012-02-29 20:43

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by q6600 (Post 1171695)
Any help for you guys

Looks like that is not my latest compiled version, all you have in there is the openssl libraries (libcrypto and libssl). All the other libraries should already be on the system (check /usr/lib). To get the openssl libraries try this
Code:

sudo apt-get install openssl
.

q6600 2012-02-29 20:54

Re: [Tutorial] Pentesting Wireless Networks
 
I have the latest version of openssl. I install the first version of hydra 7.2 and is working fine.

StefanL 2012-03-02 12:23

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by q6600 (Post 1172278)
I have the latest version of openssl. I install the first version of hydra 7.2 and is working fine.

Yep, for now the first version is best until I have sorted out the dependencies. I have now a compiled version that only requires openssl 0.9.8n, but still looking into getting all the other dependencies (like libssh, libidn, etc.) in order so that people can run the version with the most functionality enabled. Should be out over the weekend.

stevomanu 2012-03-10 19:24

Re: [Tutorial] Pentesting Wireless Networks
 
Well i loaded up charon and it aint in english does anybody know how to change it ??

seems like a cool app from what research i done on it ...

Mohammed Muid 2012-03-10 20:10

Re: [Tutorial] Pentesting Wireless Networks
 
i tried to run driftnet. how to do that? i failed. can you please help me

shockingfm 2012-03-15 01:09

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by stevomanu (Post 1177558)
Well i loaded up charon and it aint in english does anybody know how to change it ??

seems like a cool app from what research i done on it ...

Stevomanu

How did you load up Charon?
I installed it but no icon, so i went to xterminal under sudo gainroot and it then typed "charon2.0" but get permission denied

any help would be fantastic

Nick

stevomanu 2012-03-15 01:12

Re: [Tutorial] Pentesting Wireless Networks
 
Try this command as root

Code:

java -jar /opt/charon2.0.1-karam/CHARON_2.0.1.jar
Quote:

Originally Posted by shockingfm (Post 1179617)
Stevomanu

How did you load up Charon?
I installed it but no icon, so i went to xterminal under sudo gainroot and it then typed "charon2.0" but get permission denied

any help would be fantastic

Nick


shockingfm 2012-03-15 01:27

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by stevomanu (Post 1179618)
Try this command as root

Code:

java -jar /opt/charon2.0.1-karam/CHARON_2.0.1.jar

Genius!! thanks!

errm its in French. Damn! do we know if anyone is working on it?

Mohammed Muid 2012-03-15 01:42

Re: [Tutorial] Pentesting Wireless Networks
 
how to load up driftnet too. i also tried many commands.

spuddy101 2012-03-15 12:01

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by shockingfm (Post 1179622)
Genius!! thanks!

errm its in French. Damn! do we know if anyone is working on it?

i just open xterm and typed charon and it worked fine for me.

shockingfm 2012-03-15 13:12

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by spuddy101 (Post 1179784)
i just open xterm and typed charon and it worked fine for me.

thanks spuddy! that works too!

what the hell was i doing before to make it not work?!

Mohammed Muid 2012-03-15 13:43

Re: [Tutorial] Pentesting Wireless Networks
 
how to run driftnet then? just typing driftnet doesnot work. i enabled ip forwarding. how to use driftnet? i also created a folder in MyDocs for the images to be stored there

stevomanu 2012-03-15 14:01

Re: [Tutorial] Pentesting Wireless Networks
 
This might help , great site for other security stuff so i dont see why not ....

http://www.securitytube.net/video/664


Quote:

Originally Posted by Mohammed Muid (Post 1179814)
how to run driftnet then? just typing driftnet doesnot work. i enabled ip forwarding. how to use driftnet? i also created a folder in MyDocs for the images to be stored there


one1002 2012-03-15 15:58

Re: [Tutorial] Pentesting Wireless Networks
 
i'm wondering why i'm getting

"E: Couldn't find package xxxx"

when i apt-get install...?

stevomanu 2012-03-15 16:16

Re: [Tutorial] Pentesting Wireless Networks
 
Well it would help if we had a clue as to what your trying to install. ..

Quote:

Originally Posted by one1002 (Post 1179870)
i'm wondering why i'm getting

"E: Couldn't find package xxxx"

when i apt-get install...?


one1002 2012-03-15 16:33

Re: [Tutorial] Pentesting Wireless Networks
 
was trying to install the whole thing..

"apt-get install nmap driftnet yamas wireshark charon etc2"

fixed it by enabling the repos in app manager..i've disabled it before because i'm using FAPman instead of "apt-get install"..cheers!

btw, charon is in what language?lol..can't seem to understand it...it's nice to have a GUI for mdk3...hmmpph!! =D

Mohammed Muid 2012-03-16 02:46

Re: [Tutorial] Pentesting Wireless Networks
 
i get this while trying to open charon::

Nokia-N900:~# java /jar /opt/charon2.0.1-karam/CHARON_2.0.1.jar
Exception in thread "main" java.lang.NoClassDefFoundError: /jar
Caused by: java.lang.ClassNotFoundException: .jar
at java.net.URLClassLoader$1.run(URLClassLoader.java: 217)
at java.security.AccessController.doPrivileged(Native Method)
at java.net.URLClassLoader.findClass(URLClassLoader.j ava:205)
at java.lang.ClassLoader.loadClass(ClassLoader.java:3 21)
at sun.misc.Launcher$AppClassLoader.loadClass(Launche r.java:294)
at java.lang.ClassLoader.loadClass(ClassLoader.java:2 66)
at java.lang.ClassLoader.loadClassInternal(ClassLoade r.java:334)
Could not find the main class: /jar. Program will exit.
Nokia-N900:~#

one1002 2012-03-16 04:34

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by Mohammed Muid (Post 1180104)
i get this while trying to open charon::

Nokia-N900:~# java /jar /opt/charon2.0.1-karam/CHARON_2.0.1.jar
Exception in thread "main" java.lang.NoClassDefFoundError: /jar
Caused by: java.lang.ClassNotFoundException: .jar
at java.net.URLClassLoader$1.run(URLClassLoader.java: 217)
at java.security.AccessController.doPrivileged(Native Method)
at java.net.URLClassLoader.findClass(URLClassLoader.j ava:205)
at java.lang.ClassLoader.loadClass(ClassLoader.java:3 21)
at sun.misc.Launcher$AppClassLoader.loadClass(Launche r.java:294)
at java.lang.ClassLoader.loadClass(ClassLoader.java:2 66)
at java.lang.ClassLoader.loadClassInternal(ClassLoade r.java:334)
Could not find the main class: /jar. Program will exit.
Nokia-N900:~#

open terminal, type
Code:

charon
..

don't have to be root i guess..i launched it that way..and perhaps u don't have icedtea6 installed?

Mohammed Muid 2012-03-16 05:41

Re: [Tutorial] Pentesting Wireless Networks
 
thanks. that did it. itreid that before but dint work. charon is in diff language.i cant hange the language to english. how to do that sir?

one1002 2012-03-16 07:00

Re: [Tutorial] Pentesting Wireless Networks
 
Quote:

Originally Posted by Mohammed Muid (Post 1180135)
thanks. that did it. itreid that before but dint work. charon is in diff language.i cant hange the language to english. how to do that sir?

i have no idea how to change it to english..i think u have to change the jar files..but i can't seem to b able to edit it using jar editor..lol..and i dont know which file to edit as well..haha

Mohammed Muid 2012-03-16 11:00

Re: [Tutorial] Pentesting Wireless Networks
 
So whats the point? Cant use it anyway. I can perform b a and d with xterminal. Works like a charm. So the peolple who doesnt kno this language cannot use it? Y wud even any1 use this language.


All times are GMT. The time now is 20:06.

vBulletin® Version 3.8.8