ARP-Spoofing on WiFi
#1
Posted 08 March 2009 - 02:37 PM
#2
Posted 08 March 2009 - 02:50 PM
Since WiFi is Wireless, you can put your card into promiscuous mode and just see all the traffic, since it's radio waves.
Here you seem to have some misconceptions again. If the traffic is unencrypted, then you have just packets. If the traffic is encrypted, then you have to know the key and then you use it as if you were connected to any other network and sniff the traffic in the same way, with the decryption being done on the fly. I really have no idea what you mean by "separate the packets from what specific router they were on", or "pluck the passwords from there"? The router question makes no sense and I don't know what passwords you're talking about.Then later you can run the capture file through some software that can decrypt it, given you have the password, and then seperate the packets from what specific router they were on, and then just pluck out the passwords from there?
Only by asking for a DHCP lease you do actually leave traces.Or just make it simpler and actually connect to the WiFi zone, but sniff all the packets being transferred on it. That way, it's completely untraceable, unlike ARP-spoofing the whole network.
#3
Posted 08 March 2009 - 03:03 PM
#4
Posted 08 March 2009 - 04:35 PM
#5
Posted 08 March 2009 - 05:59 PM
Anyway, I am not too sure what your idea is, but I'll tell you this: Just connect to an AP, ARP poison, and then start a sniffer (best for password capturing is ettercap). To make sure that their is actually traffic, I suggest you use something like kismet or airodump to check the data flow.
#6
Posted 08 March 2009 - 06:40 PM
Edited by thepcdude, 08 March 2009 - 06:40 PM.
#7
Posted 08 March 2009 - 06:41 PM
#8
Posted 08 March 2009 - 06:47 PM
The problem with arp poisoning is that it leaves traces. Sometimes it's better to just capture everything passively (such as open networks at a train station and such) however the only problem with this is that packets cannot be modified so tools such as sslstrip wont work.
Exactly!
#9
Posted 08 March 2009 - 08:33 PM
Where do you find these good admins? Cuz there certainly aren't any in my town, especially at my local library, high school, etc. Besides so long as your not attempting to steal credit card numbers and do stupid stuff like that I'd say you've got nothing to worry about...well almost nothing anyway.Yes, that is essentially what I do. But the point is that I do not want to ARP spoof. Good system admins can see when their network is being ARP spoofed. Thus, sniffing the radio waves right out of the air would be the thing for me.
#10
Posted 08 March 2009 - 08:57 PM
Where do you find these good admins? Cuz there certainly aren't any in my town, especially at my local library, high school, etc. Besides so long as your not attempting to steal credit card numbers and do stupid stuff like that I'd say you've got nothing to worry about...well almost nothing anyway.Yes, that is essentially what I do. But the point is that I do not want to ARP spoof. Good system admins can see when their network is being ARP spoofed. Thus, sniffing the radio waves right out of the air would be the thing for me.
An IDS can pick that up no problem. But that all depends on who's monitoring the IDS and what they're doing about it.
#11
Posted 08 March 2009 - 09:05 PM
Edited by phr34kc0der, 08 March 2009 - 09:06 PM.
BinRev is hosted by the great people at Lunarpages!













