Menu

Main Menu
Talk Get Daily Search

Member's Online

    User Name
    Password

    [Announce] Yet another MITM attack script (Yamas-ARM)

    Reply
    Page 25 of 48 | Prev | 15   23     24   25   26     27   35 | Next | Last
    Unhuman | # 241 | 2011-06-30, 14:56 | Report

    Don't abuse the script on foreign networks. If it was your network you would of known if those numbers were a password.

    EDIT:

    late by 3 seconds

    Edit | Forward | Quote | Quick Reply | Thanks

     
    comaX | # 242 | 2011-06-30, 15:00 | Report

    Originally Posted by Unhuman View Post
    Don't abuse the script on foreign networks. If it was your network you would have known if those numbers were a password.

    EDIT:

    late by 3 <i>minutes</i>
    <useless post>Mouahahaha*, beat ya !</useless post>

    *French evil laugh

    Edit | Forward | Quote | Quick Reply | Thanks

    Last edited by comaX; 2011-06-30 at 15:06.

     
    Kabouik | # 243 | 2011-06-30, 15:13 | Report

    Damn frog-eater!*

    Still no success at trying Yamas there. I have no idea of what is the problem in my case, since I don't have all the error logs that Price reported, just the one I quoted above.

    I can't try it again for the moment 'cause I'm at work, and attacking the wifi of the laboratory/university would be a suicide I guess.



    * J'en suis un moi-même. :[

    Edit | Forward | Quote | Quick Reply | Thanks

    Last edited by Kabouik; 2011-06-30 at 15:16.

     
    AgogData | # 244 | 2011-06-30, 15:18 | Report

    Originally Posted by comaX View Post
    Hmm... You sir are a bad student ! Since you're assuming it may be the password, it means you don't know it. If you don't know it, it's not yours. I'm sorry, but I won't help you for that.
    Here's just a hint : we are parsing the log.

    You should use the script on your own connection and then get log into a maximum of sites to know what the output should look like.

    The saving location is just a variable now, so you can change it to whatever suits you Saturn used this location because of some problem with MyDocs not being always available or something.
    yes its not my network, its not illegal here but its rude
    anyway i didn't mean any harm to the...victim, just using my n900's ability

    Edit | Forward | Quote | Quick Reply | Thanks

     
    teemui | # 245 | 2011-06-30, 15:18 | Report

    i have this "egrep: bad regex" error too every time i try it. i have all depencies installed, no matter what website i try i allways get this error

    Edit | Forward | Quote | Quick Reply | Thanks

     
    mr_pingu | # 246 | 2011-06-30, 15:22 | Report

    Runned the attack this day and worked as it should, except that the victim pc got sometimes a page with only the letters:

    ht

    then reload gives a page with:

    hmtl layout code of that page without images

    another reload gives:

    The actual page, with good layout =D

    On the phone side everything works. Gonna need to find my flashdrive with backtrack again, and test if I get these pages when running from backtrack also. Last time I tried a mitm-attack this wonderful script wasn't available :P Thanks for making me this easy, ComaX

    Edit | Forward | Quote | Quick Reply | Thanks

     
    teemui | # 247 | 2011-06-30, 16:04 | Report

    rebooted the n900, now i get following in the password window:

    BusyBox v1.18.5 (Debian 1.18.5power1) multi-call binary.

    No help available.

    it flashes every now and then, the grep error dissappeared but i stil get no other output than this..

    Edit | Forward | Quote | Quick Reply | Thanks

     
    comaX | # 248 | 2011-06-30, 17:02 | Report

    Originally Posted by AgogData View Post
    yes its not my network, its not illegal here but its rude
    anyway i didn't mean any harm to the...victim, just using my n900's ability
    Well, I don't know where you live, but I'd bet my *** it is pretty much illegal ^^ Anyway, you do whatever you want, it's not like we're the cops or about to call them !

    Originally Posted by teemui View Post
    rebooted the n900, now i get following in the password window:

    BusyBox v1.18.5 (Debian 1.18.5power1) multi-call binary.

    No help available.

    it flashes every now and then, the grep error dissappeared but i stil get no other output than this..
    So the problem definitively comes from some error at an installation/package level... Since I do not have the N900 I can't help much, but I'm sure others members will

    Originally Posted by mr_pingu View Post
    Runned the attack this day and worked as it should, except that the victim pc got sometimes a page with only the letters:

    ht

    then reload gives a page with:

    hmtl layout code of that page without images

    another reload gives:

    The actual page, with good layout =D

    On the phone side everything works. Gonna need to find my flashdrive with backtrack again, and test if I get these pages when running from backtrack also. Last time I tried a mitm-attack this wonderful script wasn't available :P Thanks for making me this easy, ComaX
    Yeahp, not my fault ! That's sslstrip's work... I mean, sometimes it will just be fine, but most of the time you'll have to reload once. Let's hope that will be fixed in sslstrip 1.0.
    About your BT drive, the original script will ony work on BT5. The BT4r2 version is still available though.

    Originally Posted by Kabouik View Post
    Damn frog-eater!*

    Still no success at trying Yamas there. I have no idea of what is the problem in my case, since I don't have all the error logs that Price reported, just the one I quoted above.

    I can't try it again for the moment 'cause I'm at work, and attacking the wifi of the laboratory/university would be a suicide I guess.



    * J'en suis un moi-même. :[
    Yeah, no. You can do that, but we don't want to know ! And yes, that would be suicide ! Maybe even for your phone if there is a lot of traffic going on...
    Don't hesitate to send me your logs (edited if you want, but I could care less about your/their () passwords) by mail and any output you have. You can even write them in French
    For the small-talk part, I actually wrote most of the structure of the script while at university. Never tested it there though, since you need you name and pass to connect to the network... So matching my name to some weird-*** ARPs wouldn't have been too much of a hassle.

    Edit | Forward | Quote | Quick Reply | Thanks

    Last edited by comaX; 2011-06-30 at 17:06.
    The Following User Says Thank You to comaX For This Useful Post:
    Estel

     
    mr_pingu | # 249 | 2011-06-30, 17:23 | Report

    Originally Posted by comaX View Post


    Yeahp, not my fault ! That's sslstrip's work... I mean, sometimes it will just be fine, but most of the time you'll have to reload once. Let's hope that will be fixed in sslstrip 1.0.
    About your BT drive, the original script will ony work on BT5. The BT4r2 version is still available though.

    Don't worry I have a strange mood and am installing bt5 on local drive

    Edit: Yeah, I f###ed up, grub rescue unknown filesystem yeah :d

    Edit | Forward | Quote | Quick Reply | Thanks

     
    teemui | # 250 | 2011-06-30, 17:39 | Report

    Finally i got this to work.. if someone still have same issues i had, in this order what i did:
    reinstalled yamas
    reinstalled ettercap
    reinstalled sslstrip
    im not sure if it messed everything, but first time i installed first ettercap then sslstrip and last yamas..
    Thank you all, specially comaX

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Page 25 of 48 | Prev | 15   23     24   25   26     27   35 | Next | Last
vBulletin® Version 3.8.8
Normal Logout