Just to give you some information on what kind of setup i have going. Im running Windows Vista Ult. as my main operating system. I have VMware server running ( VMware-server-2.0.1-156745) where i have backtrack 3 running with persistent changes so its not a live boot, and i have Windows XP SP3 running. Both virtual machines are using a bridged connection with the main machine. Each machine gets an IP from the DHCP, and I have no problems accessing the internet, pinging or any kind of communication between the OS's. I'm a netsec student, and use this virtual environment to test exploiting different vulnerabilities, and make videos of doing so. I have had no problems whatsoever with ettercap up until a few days ago. For some reason the program isn't able to successfully poison. When i chk_poison, there is no poisoning between my targeted machine.
The ettercap command im using.
ettercap -T -q -M arp:remote -P dns_spoof /<target_ip>/ // (obviously replacing the <target_ip> with the appropriate address)
I have used wireshark to analyze the packets to compare a successful poison vs a unsuccessful one in wireshark. I have found the problem and ettercap is simply not rewriting the DST mac with the spoofed one. If i get any replies i can upload the wireshark log...
Some steps Ive taken to try and fix the problem.
I made sure the etter.dns file have the correct ip. **** In backtrack
Restart all the machines, restart the router and cable modem.
ipconfig /flushdns and clear the cache in IE7 ***** on the target machine
echo "1" > /proc/sys/net/ipv4/ip_forward *** In backtrack
Im not sure if your iptable rule sets reset once your reboot, but i have checked my iptables -L in backtrack and all is good. I can upload a copy if anyone wants to see.
I thought there might be some kind of issue with Vista and communicating between the machines, so i reset the tcp/ip stack with netsh int ip reset reset.log still nothing........
If anyone could help me out id appreciate it. If you need any more information about my system or anything let me know.
Thanks
L3g10n
Edited by L3g10n, 16 June 2009 - 06:41 PM.












