📄 cable.html
字号:
<br><b><TracerT></b> so there will be a lecture on ASCII
<br><b><TracerT></b> ?
<br><b><Leper></b> :)
<br><b><mikestevens></b> you would hijack copperd's IP
<br><font color="#FF0000">*** TracerT is now known as [T]racer[T]</font>
<br><b><Matt></b> cheese crackers?
<br><b><mikestevens></b> and log onto IRC as him
<br><b><mikestevens></b> and start takeing back all the crackers he
gave out
<br><font color="#FF0000">*** Quits: SpiderMan (Ping timeout)</font>
<br><b><mikestevens></b> and not impersonate an admin
<br><font color="#FF0000">*** Joins: ToRmEnThOr</font>
<br><b><mikestevens></b> well anyways
<br><b><mikestevens></b> onto the cool part
<br><font color="#FF0000">*** Joins: MasJCrasJ</font>
<br><font color="#FF0000">*** Joins: SpiderMan</font>
<br><font color="#FF0000">*** ChanServ sets mode: +o SpiderMan</font>
<br><b><mikestevens></b> intercepting downsteam traffic
<br><font color="#FF0000">*** mikestevens sets mode: +m</font>
<br><b><Sup|ED-209|Craft></b> this is better then school lecture, why
not make 'BSRF School' ? :P
<br><b><mikestevens></b> first thing first
<br><b><Matt></b> mikestevens, are there any time when you can't become
the stealer?
<br><b><Matt></b> bobbie: node position?
<br><b><Ralph></b> later
<br><font color="#FF0000">*** Quits: Ralph (Quit: Leaving)</font>
<br><b><mikestevens></b> Matt: when you are not on the same router
<br><font color="#FF0000">*** Quits: K1llabee (Connection reset by peer)</font>
<br><font color="#FF0000">*** MasJCrasJ is now known as _MasjCrasj-</font>
<br><b><mikestevens></b> routers cover alot of ground though
<br><b><mikestevens></b> usually a few mile range
<br><b><Sup|ED-209|Craft></b> mikestevens: so the data to the IP that
is not be used, goes to the router?
<br><b><mikestevens></b> so people at school, neighbors, etc are all
potential victims
<br><b><mikestevens></b> that slut next door
<br><b><mikestevens></b> etc...
<br><font color="#FF0000">*** mikestevens sets mode: -m</font>
<br><b><Matt></b> mikestevens, I was under the impression most cable
companies cluster their routers and create a mesh network?
<br><b><Sup|ED-209|Craft></b> later ppl
<br><b><mikestevens></b> Sup|ED-209|Craft: I don't really understand
what you said
<br><b><Sup|ED-209|Craft></b> i will xplain later
<br><font color="#FF0000">*** Quits: _MasjCrasj- (Quit: )</font>
<br><b><mikestevens></b> Matt: they have local routers and link them
with FDDI
<br><b><Sup|ED-209|Craft></b> later
<br><font color="#FF0000">*** Quits: Sup|ED-209|Craft (Quit: )</font>
<br><b><mikestevens></b> then the FDDI ring goes to the local datacenter
<br><font color="#FF0000">*** Joins: nebunu</font>
<br><font color="#FF0000">*** Quits: SileNceR (Ping timeout)</font>
<br><b><mikestevens></b> anyways onto intercepting traffic if no one
has any more questions / comments
<br><font color="#FF0000">*** mikestevens sets mode: +m</font>
<br><b><mikestevens></b> ok
<br><b><mikestevens></b> first we need to know a little more about the
network
<br><b><Matt></b> afk
<br><b><mikestevens></b> you have the cable router, your cable modem/router,
and your PC
<br><b><mikestevens></b> the cable modem is nothing more than a bridge
<br><b><mikestevens></b> meaning it sees traffic on both sides and seamlessly
forwards as needed
<br><b><[T]racer[T]></b> there gonna be an lecture on streamz here?
<br><b><[T]racer[T]></b> *stringz
<br><font color="#FF0000">*** Joins: K3rNEL[PAn1C]</font>
<br><font color="#FF0000">*** Parts: nebunu</font>
<br><font color="#FF0000">*** Joins: Pupp3tM</font>
<br><font color="#FF0000">*** ChanServ sets mode: +v Pupp3tM</font>
<br><b><mikestevens></b> the 3100 surfboard has a webserver which you
can play with from inside your network
<br><b><mikestevens></b> http://192.168.100.1/
<br><b><mikestevens></b> I found the IP by sniffing
<br><b><mikestevens></b> and I saw IGMP traffic coming from that IP
<br><b><mikestevens></b> so I browsed to it
<br><b><mikestevens></b> anyways, the bridge is based on MAC addresses
<br><font color="#FF0000">*** Quits: Pupp3tM (Quit: )</font>
<br><b><mikestevens></b> so if it sees your MAC behind the bridge it
will let in traffic that is destined to that MAC
<br><b><mikestevens></b> the outside has no clue what is going on with
the Cable modem
<br><b><mikestevens></b> another issue
<br><b><mikestevens></b> not all cable modems will detect the MAC how
mine does
<br><b><mikestevens></b> you may have to try arp packets to fool it
into it
<br><b><mikestevens></b> I will provide both ways here
<br><b><mikestevens></b> so onto the interception
<br><b><mikestevens></b> first you want to find the targets MAC
<br><b><mikestevens></b> get onto their subnet
<br><b><mikestevens></b> and ping them or something
<br><b><mikestevens></b> then do an arp -an and write down their MAC
<br><b><mikestevens></b> also do an ifconfig -a and write down your
MAC
<br><b><mikestevens></b> it is best to hard boot your cable modem at
this point
<br><font color="#FF0000">*** Quits: Prophecy2K1 (Ping timeout)</font>
<br><b><mikestevens></b> that way it clears the memory of MACs
<br><b><mikestevens></b> this is done by pressing the little reset button
in the back or however you documentation says so
<br><b><mikestevens></b> it should take a few minutes up to 30 to get
back on
<br><b><mikestevens></b> so in the time being
<br><b><mikestevens></b> you want to stop all services
<br><b><mikestevens></b> then bring down eth0
<br><b><mikestevens></b> then type this with the target's MAC in place
of it
<br><b><mikestevens></b> ifconfig eth0 hw ether 00:00:00:00:00:00
<br><b><mikestevens></b> bring the interface up with your IP address
and normal settings
<br><b><mikestevens></b> add your default gateway
<br><b><mikestevens></b> and ping the router a few times till it works
<br><b><mikestevens></b> take back down the interface
<br><b><mikestevens></b> and bring it up again with your settings
<br><b><mikestevens></b> start up your services again
<br><b><mikestevens></b> and ping the router again to make sure your
are on
<br><b><mikestevens></b> you should now be getting the target's downstream
traffic
<br><font color="#FF0000">*** Joins: Prophecy2K1</font>
<br><font color="#FF0000">*** Quits: Matt (Ping timeout)</font>
<br><b><mikestevens></b> you can use all your fun sniffer tools to invade
their privacy,etc...
<br><b><mikestevens></b> I will open up a Q&A section while I get
the code mods for the ARP section
<br>*** mikestevens sets mode: -m
<br><b><mikestevens></b> any questions?
<br><font color="#FF0000">*** Joins: UraniumD</font>
<br><b><[T]racer[T]></b> yes
<br><b><mikestevens></b> ok
<br><b><Ellis_D></b> does the person whose traffic we are stealing have
a way of knowing we are doing this?
<br><font color="#FF0000">*** Parts: UraniumD</font>
<br><b><ToRmEnThOr></b> i think so
<br><font color="#FF0000">*** Joins: MosdestMouse</font>
<br><b><mikestevens></b> no
<br><b><[T]racer[T]></b> NM
<br><b><mikestevens></b> they can't see it
<br><b><shellfish></b> i havnt follow this very well, but is this secure?
are the cops gonna come knocking on your door or what?
<br><b><ToRmEnThOr></b> no?
<br><b><mikestevens></b> your cable modem silently passes on the traffic
to you
<br><b><Ellis_D></b> hm
<br><b><mikestevens></b> probally not
<br><b><ToRmEnThOr></b> cool
<br><b><mikestevens></b> unless someone checks on your cablemodem
<br><b><mikestevens></b> hijacking is a little riskier
<br><b><[T]racer[T]></b> and what if someone does it?
<br><b><mikestevens></b> they will probally just think the cable is
out
<br><b><mikestevens></b> interception is less risky
<br><b><mikestevens></b> well first they have to prove you did it on
purpose,etc
<br><b><[T]racer[T]></b> but if noone sees my cabel modem?
<br><b><mikestevens></b> but if you don't tell anyone they probally
will never know
<br><b><[T]racer[T]></b> hehe
<br><b><mikestevens></b> actually if you bring up the interface (when
you are using their MAC as your MAC)
<br><b><mikestevens></b> with a local IP
<br><b><mikestevens></b> sometimes the CM will see that
<br><b><[T]racer[T]></b> but on some External cabel modems there is
a way to connect to the modem
<br><b><[T]racer[T]></b> from the local machine
<br><b><[T]racer[T]></b> and check what's up there
<br><b><mikestevens></b> and there will be no traffic hitting the real
network (cable network)
<br><b><[T]racer[T]></b> *in there
<br><b><Edrin></b> well, in this case you are using spoofed MACs and
spoofd IPs on the "same cable" so it would be extremly dificult for others
to find you (well, if there are only 2 computers on the cable... anyway:
police does not know what an arp table is
<br><font color="#FF0000">*** Joins: Nokio</font>
<br><b><[T]racer[T]></b> LOL
<br><b><mikestevens></b> lol
<br><b><mikestevens></b> good point
<br><b><Nokio></b> hey guys
<br><b><mikestevens></b> anyways for the other method of getting your
CM to see you
<br><b><mikestevens></b> I made a simple mod to arpspoof.c
<br><b><mikestevens></b> of dsniff
<br><font color="#FF0000">*** Quits: Leper (Quit: Leaving)</font>
<br><b><mikestevens></b> I commented out the arp_send routine on line
193
<br><font color="#FF0000">*** Quits: gUeSt51 (Quit: Leaving)</font>
<br><b><SpiderMan></b> DF: I'm going to DCC the linux networking log
to you, ok?
<br><b><mikestevens></b> you can get the CM to see you like this with
the modified arpspoof
<br><b><Nokio></b> hey all, is the lecture over?
<br><font color="#FF0000">*** Joins: vanished[coding[</font>
<br><font color="#FF0000">*** Parts: vanished[coding[</font>
<br><b><mikestevens></b> ./arpspoof -t victimip victimip
<br><b><mikestevens></b> then controlC it
<br><b><mikestevens></b> it will send out the needed packets saying
their IP is their MAC
<br><b><mikestevens></b> but
<br><b><mikestevens></b> the important part
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -