maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Applications (https://talk.maemo.org/forumdisplay.php?f=41)
-   -   [Announce] Yet another MITM attack script (Yamas-ARM) (https://talk.maemo.org/showthread.php?t=73988)

comaX 2011-07-04 12:13

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by casper27 (Post 1044124)
@comaX
Yeah I noticed maemo.org did not work because its sent in md5. It should be possible to crack with John the Ripper. Or even a MD5 cypher online. I will have a go.

Yeah, well, for me trying to crack md5 is a waste of time ! If you have a botnet and a nice online md5 cracker (I did know one, but forgot...) you can have a go, sure. But on your own, even with some high tech two-gpu CUDA cracking gear, it can take forever...

comaX 2011-07-05 13:31

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Hi guys ! I just moved in, so I'm on a shitty, free wifi connection so I can't test sh|t, which means I can't work on DNS spoofing and all... I don't know when I'll get a decent connection, so just wait and see ! Meanwhile I can still bring support, and modify things here and there, so keep the feedback coming !

mauron85 2011-07-06 08:27

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
I have no problem with installation, however MITM doesn't work.

When I invoke script, I can see both ettercap and password terminal window running.

Victim (me) is running Windows 7.
arp -a shows that victim is using spoofed (N900) gateway.

I cannot browse internet on victim machine, (or at least it's to laggy). SSLStrip is not working (tried on facebook).

When I invoke iptables --list on N900 there are no rules.

comaX 2011-07-06 18:45

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
That's weird to say the least ! Thanks for the detailed symptoms by the way ;)
So, according to what you say, MITM is in fact working since you're using a spoofed gateway !
Now, about it being laggy, that's normal : even when I had an optic fiber connection (soon to come back I hope...) it was laggy during the attack.
Did you go as far as entering a pass for FB ?

For the iptables --list, well, there should be since we create one ! Try to enter it manually perhaps. (look at the script source, or sslstrip's website)
Were you root when doing this ? (I guess yes, but who knows !)

Ps : "Dear journal, I now have been on a shitty connection for a week. It's becoming unbearable."

Estel 2011-07-06 20:58

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by comaX (Post 1045962)
Ps : "Dear journal, I now have been on a shitty connection for a week. It's becoming unbearable."

Next entry: "Temptation to perform phishing attack on neighbourn's WPA2 password is growing hard to resist" ;) Sorry, can't stop myself from posting that.

stevomanu 2011-07-06 21:50

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
I start yamas via the desktop icon an im presnted with this error highlighted in black , also seems the script is not working .....

http://dl.dropbox.com/u/10188212/scr...706-224701.png

I dont get that error in i open xterminal as root an type " yamas " the error is gone but the script doesnt work at all not sure whats gone wrong ...

i ran yamas -d an all is fine there ...

mauron85 2011-07-07 08:22

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Did you go as far as entering a pass for FB ?
yes, but it was neccessary to do couple of page refreshs (because of laggy connection). SSLStrip didn't do the job - didn't redirect to non-ssl facebook.

I think the main problem is missing rule for iptables. I'll try (as you suggesting) add rule manually and let you know.

Of course I was invoking script as root.

yamakasi 2011-07-07 19:23

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
1 Attachment(s)
do I have to install power kernel and bleeding-edge w1251 driver ?
the script is not able to get any passwords, i am getting this error :

comaX 2011-07-10 16:21

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
HI everyone !

To the guys reporting errors, I unfortunately can't help you... It seems launching it with the icon is buggy, for some reason...

@yamakasi (smells like some fellow French there, ain't it ?) : update your iptables ! Maybe an apt-get will do, don't know !

Some dude contacted me from the BT forum to work on a ARM version (and not just N900 or maemo). So apart from places to save files, nothing much should change user-side. But if achieved, it should be compatible with at least maemo and BT-ARM. Which I think would be pretty awesome !

I'll keep you in touch !

Cheers !

mauron85 2011-07-11 20:01

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
comaX I have couple questions for you. Probably answering them, can exclude some possible environment setup problems.

Are you using nokia stock or power kernel?
And are you using stock wlan or bleeding edge drivers?
Are using default busybox or enhanced?

casper27 2011-07-11 20:15

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by yamakasi (Post 1046564)
do I have to install power kernel and bleeding-edge w1251 driver ?
the script is not able to get any passwords, i am getting this error :

Edited as power kernel is not needed but I don't think you have iptables installed correctly.
What is the output of

Code:

sudo iptables -d

comaX 2011-07-12 11:04

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by mauron85 (Post 1049105)
comaX I have couple questions for you. Probably answering them, can exclude some possible environment setup problems.

Are you using nokia stock or power kernel?
And are you using stock wlan or bleeding edge drivers?
Are using default busybox or enhanced?

As stated in the first post I made here, I do not own an N900... So I'll let others who have the script wroking answering those questions !

AgogData 2011-07-12 12:09

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by mauron85 (Post 1049105)
comaX I have couple questions for you. Probably answering them, can exclude some possible environment setup problems.

Are you using nokia stock or power kernel?
And are you using stock wlan or bleeding edge drivers?
Are using default busybox or enhanced?

its working fine with me using the menu icon
- power kernel 47
- bleeding edge
- enhanced (i guess, by installing yamas via app manager it replaced my busybox so i think its the enhanced one)

comaX, how can i know how many users are there in the network and their IPs ?

shawwawa 2011-07-12 12:17

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by AgogData (Post 1049463)
comaX, how can i know how many users are there in the network and their IPs ?

ARP-SCAN should be a GOOD Tool to see the network & IPs prior to run YAMAS. :D

http://talk.maemo.org/showthread.php?p=1016651

comaX 2011-07-13 15:52

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by AgogData (Post 1049463)
its working fine with me using the menu icon
- power kernel 47
- bleeding edge
- enhanced (i guess, by installing yamas via app manager it replaced my busybox so i think its the enhanced one)

comaX, how can i know how many users are there in the network and their IPs ?

With the host discovery feature... It is asked if you want to map the network or not ^^ You have to enter [Dd] I believe !

yamakasi 2011-07-13 19:02

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by comaX (Post 1048326)

@yamakasi (smells like some fellow French there, ain't it ?) : update your iptables ! Maybe an apt-get will do, don't know !

lol, not really since you recognized the name then you must be from Sarcelles.

anyway, 'apt-get install iptables' returns that I have the newest version.

Quote:

Originally Posted by casper27
Edited as power kernel is not needed but I don't think you have iptables installed correctly.
What is the output of

Code:

sudo iptables -d

this is the output :
Code:

iptables V1.4.6: option '-d' requires an argument try 'iptables -h' or 'iptables --help' for more information
what should I put as an argument ?

comaX 2011-07-13 19:41

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Nope, not from Sarcelles but Paris ! But the movie is pretty well known here ^^

stevomanu 2011-07-16 19:44

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
when i run yamas via the app icon i am faced with this problem when i do i rescan the network

Code:

route_dst_netlink: can't find interface "wlan0"
anybody a clue as to what this means ??

Saturn 2011-07-16 20:56

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by stevomanu (Post 1052337)
when i run yamas via the app icon i am faced with this problem when i do i rescan the network

Code:

route_dst_netlink: can't find interface "wlan0"
anybody a clue as to what this means ??

what does it say if you do:
dpkg -l nmap

just curious if you testing the beta version of nmap in devel.

stevomanu 2011-07-16 22:11

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by Saturn (Post 1052360)
what does it say if you do:
dpkg -l nmap

just curious if you testing the beta version of nmap in devel.

output is this

Code:

home/user # dpkg -l nmap
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name              Version            Description
+++-==================-==================-====================================================
ii  nmap              5.59BETA1          Command line open-source network and security scanni

yes your right its the beta version im guessing ..

Saturn 2011-07-16 22:22

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
@stevomanu:

install the one in extras:
http://maemo.org/packages/package_in...l/nmap/5.50-2/

and check if it works again.

apt-get install nmap=5.50-2

stevomanu 2011-07-16 22:56

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by Saturn (Post 1052389)
@stevomanu:

install the one in extras:
http://maemo.org/packages/package_in...l/nmap/5.50-2/

and check if it works again.

apt-get install nmap=5.50-2

many thanks for your help just wanderin do you or any 1 know why it says this in ettercap

Code:

Dissector "dns" not supported (etter.conf line 70)
many thanks

oets 2011-07-17 20:33

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by yamakasi (Post 1046564)
do I have to install power kernel and bleeding-edge w1251 driver ?
the script is not able to get any passwords, i am getting this error :
http://talk.maemo.org/attachment.php...1&d=1310066597

Any fix for this yet?

stevomanu 2011-07-17 20:59

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by oets (Post 1052902)
Any fix for this yet?

i have power kernel 47 installed an only load bleeding adge drivers when i use aircrack its not needed for this script as it uses its own dependencys ...

althou the script doesnt work all the time but thats depends on your victim

comaX 2011-07-19 17:10

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
HI everyone ! I have a new website (http://comax.fr), but no referencement because of my darn former host... So if you can pay me some visits, etc. that would be cool !
And if you wrote articles about that, with my former website in it, could you update to the new one ?

Thanks in advance bros !

Also, any feedback is welcomed !

Torpedo, I think I'll use your video as an illustration for this version, are you ok with that ?

I'm still working on the maemo page but it shouldn't be too much different from the BT one !

By the way, if that interest you, there's a count of the daily use of yamas (well, that doesn't count maemo's version, unfortunately ^^) on the page ! I didn't think it was used this much !

Cheers !

(sorry for the previous posts, but it's too device related for me to bring any help...)

torpedo48 2011-07-19 17:14

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by comaX (Post 1054257)
HI everyone ! I have a new website, but no referencement because of my darn former host... So if you can pay me some visits, etc. that would be cool !

Also, any feedback is welcomed !

Torpedo, I think I'll use your video as an illustration for this version, are you ok with that ?

I'm still working on the maemo page but it shouldn't be too much different from the BT one !

By the way, if that interest you, there's a count of the daily use of yamas (well, that doesn't count maemo's version, unfortunately ^^) on the page ! I didn't think it was used this much !

Cheers !

(sorry for the previous posts, but it's too device related for me to bring any help...)

My videos are your videos, no problems about that.

BTW, I recently bought a laptop :D
Experimenting with the full BT version of YAMAS is sooo cool, I will make a video about it too, "expect us" ;)

comaX 2011-07-19 18:06

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
You just made me a happy bunny bro !
Thanks !


Have fun with it, and enjoy your laptop !

(no, the thanks button wasn't enough :p)

Saturn 2011-07-19 18:16

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
comaX,

Very nice template; the site looks really cool. well done.

If you haven't already, maybe you want to change your signature here? :)

stevomanu 2011-07-19 19:03

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by comaX (Post 1054284)
You just made me a happy bunny bro !
Thanks !


Have fun with it, and enjoy your laptop !

(no, the thanks button wasn't enough :p)

any idea what this means ??

comaX 2011-07-20 10:05

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by stevomanu (Post 1054311)

Nope... And since we don't use anything DNS-related, it's strange... Have you checked your etter.conf file ? Tried to modify anything ?

####

Quote:

Originally Posted by Saturn (Post 1054291)
comaX,

Very nice template; the site looks really cool. well done.

If you haven't already, maybe you want to change your signature here? :)

Thanks ! And yeah, I should change the sign, thanks for reminding me :)

stevomanu 2011-07-20 11:12

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by comaX (Post 1054657)
Have you checked your etter.conf file ? Tried to modify anything ?

####



Thanks ! And yeah, I should change the sign, thanks for reminding me :)

well did some googleing on this an people have said that you need to change
Code:

# if you use iptables:
  #redir_command_on = "iptables -t nat -A PREROUTING -i %iface
-p tcp --dport %port -j REDIRECT --to-port %rport"

  #redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

to

Code:

# if you use iptables:
  redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

  redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

but that never worked either so i have no idea really .... very strange

efroname 2011-07-20 12:36

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by stevomanu (Post 1054693)
well did some googleing on this an people have said that you need to change
Code:

# if you use iptables:
  #redir_command_on = "iptables -t nat -A PREROUTING -i %iface
-p tcp --dport %port -j REDIRECT --to-port %rport"

  #redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

to

Code:

# if you use iptables:
  redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

  redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

but that never worked either so i have no idea really .... very strange

Yep, exactly the same problem here. Please help us or else I'm going to throw my N900 through a skyscrapper window :@

brokensmile 2011-07-20 12:54

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
hey wen i rouched the top menu bar line i can see only twp applets in my n900 i.e volume option and battery percentage option... i cant see the all applets like fm transmetter,shortuts,internet,clock,bluetooth etc... how to get it back

comaX 2011-07-20 13:59

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by stevomanu (Post 1054693)
well did some googleing on this an people have said that you need to change
Code:

# if you use iptables:
  #redir_command_on = "iptables -t nat -A PREROUTING -i %iface
-p tcp --dport %port -j REDIRECT --to-port %rport"

  #redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

to

Code:

# if you use iptables:
  redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

  redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

but that never worked either so i have no idea really .... very strange

I don't see any difference between the two, and it isn't ettercap related at all... I don't see how iptables would interact with etter.conf...

stevomanu 2011-07-20 14:15

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by brokensmile (Post 1054784)
hey wen i rouched the top menu bar line i can see only twp applets in my n900 i.e volume option and battery percentage option... i cant see the all applets like fm transmetter,shortuts,internet,clock,bluetooth etc... how to get it back

hijack a thread why dont you lol , you need to find the write thread an post your issue there ....

stevomanu 2011-07-20 14:25

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by comaX (Post 1054815)
I don't see any difference between the two, and it isn't ettercap related at all... I don't see how iptables would interact with etter.conf...

the hashes are missing if you notice at start of the line , i googled it an thats what some different forums came up with it work for some an not others so i have no idea at all ...


plus line 70 is here

Code:

dns = 53                  # udp    53
so i cant see whats wrong

karam 2011-07-20 14:45

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
@stevomanu

i had the problem with debian-chroot
but not in maemo5
i guess it is tcpdump
try to install it
apt-get install tcpdump

if still having the problem
try to reinstall ettercap from

http://talk.maemo.org/showpost.php?p...50&postcount=1

that's how i got mine working perfectly

Saturn 2011-07-20 18:26

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by stevomanu (Post 1052398)
many thanks for your help just wanderin do you or any 1 know why it says this in ettercap

Code:

Dissector "dns" not supported (etter.conf line 70)
many thanks

From where did you install ettercap? (Unhuman's guide is the recommended here)

I'm asking since searching for this in the forums seems like it used to be a problem in older versions of ettercap. Of course your problem might be different.

EDIT: Ohh, I just noticed there was a whole page of comments I missed..

stevomanu 2011-07-20 18:33

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
not sure now but it wasnt from the link above thats for sure , so have you got a link an will check out both if i have to ..

cheers

Saturn 2011-07-20 18:35

Re: [Announce] Yet another MITM attack script (Yamas-ARM)
 
Quote:

Originally Posted by stevomanu (Post 1054981)
not sure now but it wasnt from the link above thats for sure , so have you got a link an will check out both if i have to ..

cheers

did you try to check first post? :rolleyes:


All times are GMT. The time now is 08:33.

vBulletin® Version 3.8.8