maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   OS2008 / Maemo 4 / Chinook - Diablo (https://talk.maemo.org/forumdisplay.php?f=29)
-   -   Pentesting with IT 2008 OS (https://talk.maemo.org/showthread.php?t=20648)

BlackOp333 2008-06-03 02:48

Pentesting with IT 2008 OS
 
I thought I'd start a list of pentesting tools fro the Nokia N-series, specifically using the 2008 OS.
Here's the compilation so far:
The Aircrack-ng suite (Thanks to Collin Mulliner):
http://www.mulliner.org/nokia770/fee..._0.5-1_arm.deb
(wireless tools is also available from his site: http://www.mulliner.org/nokia770/fee...s_28-1_arm.deb )

Kismet
http://www.internettablettalk.com/fo...ghlight=Kismet

Nmap
http://daveblank.com/nmap_4.50-1_armel.deb
http://www.internettablettalk.com/fo...highlight=nmap

Dsniff
http://www.mulliner.org/nokia770/fee...b1s2-1_arm.deb
(Thanks again to Mr. Mulliner. I would suggest you download his repository: http://www.mulliner.org/nokia770/mul...hinook.install)

Metasploit
http://mfresh-n800.blogspot.com/2007...work-3-on.html
(Thanks to Paul Rubens. Check out his excellent blog here: http://mfresh-n800.blogspot.com/)

Wifizoo
http://www.freedomcoder.com.ar/node/95

Ettercap
http://www.gronmayer.com/it/dl.php?id=205
(This is an excellent searchable list of repositories: http://www.gronmayer.com/it/index.ph...&system=maemo4)

If anyone has version updates or more to add to the list please say so.
Thanx

geneven 2008-06-03 03:23

Re: Pentesting with IT 2008 OS
 
Great!

What's pentesting?

Benson 2008-06-03 03:58

Re: Pentesting with IT 2008 OS
 
http://en.wikipedia.org/wiki/Penetration_test

BlackOp333 2008-06-03 17:31

Re: Pentesting with IT 2008 OS
 
Here's an addendum to the Wifizoo listing: http://www.freedomcoder.com.ar/node/100

devaler 2008-06-03 19:22

Re: Pentesting with IT 2008 OS
 
Quote:

Great!

What's pentesting?
You mean you didn't search first? ;)

brendan 2008-06-03 19:28

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by devaler (Post 188403)
You mean you didn't search first? ;)

pentesting is a term for the QA team under the employ of companies like Bic and PaperMate, that scribble with the pens coming off the production line, to ensure that each one works before it is packaged and shipped to retail stores.

a mundane and monotonous job, but someone has to do it.

fizze 2008-06-04 13:41

Re: Pentesting with IT 2008 OS
 
Nice thread! :)

Did anyone try to compile/run Yersinia on the NITs?

I haven't seen a show-stopper in the dependencies so far....

BlackOp333 2008-06-04 14:02

Re: Pentesting with IT 2008 OS
 
Try it and see. Post how iit turns out.

BlackOp333 2008-06-04 14:10

Re: Pentesting with IT 2008 OS
 
There is an arm and armel version for debian. Can anyone port this?
http://packages.debian.org/unstable/admin/yersinia

sjgadsby 2008-06-04 14:19

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by brendan (Post 188408)
pentesting is a term for the QA team under the employ of companies like Bic and PaperMate...

Ah! Thank you!

I thought it was:


fizze 2008-06-04 14:26

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by BlackOp333 (Post 188619)
There is an arm and armel version for debian. Can anyone port this?
http://packages.debian.org/unstable/admin/yersinia

Feh, some googling should have turned this up.
Well there is a ncurses-based console version. That should run. I'll try and post my results once I'm home.

Benson 2008-06-04 16:30

Re: Pentesting with IT 2008 OS
 
Well, I'd just try installing the armel Debian package first (maybe with --force-depends-version, or whatever it is; our libc is older than Lenny, but most everything works...); if that doesn't work, it's always possible to install Debian, but it's probably pretty easy to at least build the ncurses version. And they say it is ahead, not behind, the GUI version, which is good...

qwerty12 2008-06-04 17:02

Re: Pentesting with IT 2008 OS
 
1 Attachment(s)
Not much point going to the SVN for this one.

@Nokia

Please take the time to be arsed to upload a libpcap-dev package. That way I don't have to compile it from your source. Thank you for listening.

BlackOp333 2008-06-04 17:33

Re: Pentesting with IT 2008 OS
 
Great, Thanx for that, qwerty!
This is one of the reasons for the thread.

qwerty12 2008-06-04 17:35

Re: Pentesting with IT 2008 OS
 
Np :)

I haven't tested it however :/

The ncurses interface should work for sure though imho, I got some gtk warning while compiling.

BlackOp333 2008-06-04 17:52

Re: Pentesting with IT 2008 OS
 
I'm having python problems with wifizoo. I need BaseHTTPServer, SimpleHTTPServer, and CGIHTTPServer. Are these modules available for maemo. (I checked gronmayer and did not find them but don't know if they are part of another file)

qwerty12 2008-06-05 06:12

Re: Pentesting with IT 2008 OS
 
http://www.internettablettalk.com/fo...ghlight=winexe

http://www.internettablettalk.com/fo...ight=smbclient

http://www.internettablettalk.com/fo...&highlight=pft

http://www.internettablettalk.com/fo...021#post189021

(Not really pentesting though but may be useful). I'll update this post with some new software I plan to compile later.

qwerty12 2008-06-05 06:39

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by sjgadsby (Post 188625)
Ah! Thank you!

I thought it was:
[/CENTER]

Dugg for pictures.

Anyway,

[sbox-CHINOOK_ARMEL: ~/32/PHoss] > ./PHoss
PHoss (Phenoelit's own security sniffer)
(c) 1999 by Phenoelit (http://www.phenoelit.de)
$Revision: 1.13 $
./PHoss [-Ppv] [-l XXXX] [-i interface ] [-f filter]

-P Don't use destination ports for protocol identification
-p Don't use pattern matching for protocol identification
-v verbose (more increase information)
-l XX Set capture length to this value (default 1525)
-i int Use this interface
-f xx Set packet filter. See tcpdump(1) for more
-L make output linebuffered


Quote:

PHoss is a sniffer designed to find HTTP, FTP, LDAP, Telnet, IMAP4 and POP3 logins on the wire. It also sniffs the VNC challange/response handshake.
Hard to find and has great effect !
(No idea how old this one is :P)

Enjoy. Save and chmod +x. (pcap needed):
http://www.mediafire.com/?ykgygzeysmm

Also,
Quote:

Maemo Chinook
[Repository is online]
http://repository.maemo.org/
chinook | free non-free
Show packages
Dls: 28670
Status: Repository is online
Project page: http://repository.maemo.org/
last update: 06/04/2008 13:23:46 (GMT +0200)
Package:
netcat (v. 1.10-32osso1)
http://gronmayer.com/it/dl.php?id=123

That repo has netcat on it.

Also telnet is here:
http://maemo.daylessday.org/repo/dis...telnet-1.5.deb

BlackOp333 2008-06-05 12:19

Re: Pentesting with IT 2008 OS
 
Great!
Thanx for the useful post, qwerty!
Got the wifizoo to stop giving me those errors by installing the python daemon.
Who'd a thunk?

BlackOp333 2008-06-05 12:59

Re: Pentesting with IT 2008 OS
 
How do I run PHoss?
I did the chmod -x

qwerty12 2008-06-05 14:23

Re: Pentesting with IT 2008 OS
 
Make sure you aren't trying to run it off a memory card. (Use the file manager to move it to a folder on the flash).

And it's chmod +x

(- would remove an executable permission, not what we want to do here :))

poxika 2008-06-05 15:19

Re: Pentesting with IT 2008 OS
 
It's good to list programs that have been compiled for IT2008, but because the kernel is missing NAT iptables, dsniff and ettercap are less than useful for pentesting.

qwerty12 2008-06-05 15:33

Re: Pentesting with IT 2008 OS
 
apt-get source kernel-source-rx-34 and you can compile your own.

BlackOp333 2008-06-06 15:40

Re: Pentesting with IT 2008 OS
 
Here's another addition: Hydra!
Quote:

Originally Posted by jolouis (Post 161470)
Dan,

It's not perfect and sort of a half-way port, but you can grab the deb file from here:
http://www.electronicproductonline.c....5.4_armel.deb

In order for it to work you may need to have OpenSSL installed, I'm not entirely sure. I had to install it to compile Hydra properly, and on my testing tablet it was already there so I didn't have any trouble. If you need it it's in the maemo repositories (it may even be on the tablet already).

I don't know if this app actually works or not as I don't have something to try and crack with it and have no idea how to use the app, but it seems to run and will do basic tests without generating errors. The interface leaves a bit to be desired in terms of usability especially if the onscreen keyboard pops up, but generally the thing functions.

Almost forgot... to use the thing: install the deb file, and then open up xterm and just type
xhydra

the Xterm will stay open and the hydra app will pop up; sure a .desktop file would be nice and all, but I'm too busy right now for all that!

Thanks,
-Rob


qwerty12 2008-06-06 16:35

Re: Pentesting with IT 2008 OS
 
Ok, here is "SIPcrack - SIP login dumper/cracker"

I thought it would be fun seeing as we have inbuilt SIP client on OS2008.

I'm trying to compile some other stuff atm so... :)

http://www.mediafire.com/?3rhdcggfmdl

qwerty12 2008-06-06 17:06

Re: Pentesting with IT 2008 OS
 
2 Attachment(s)
Enjoy,

Netdiscover

Netdiscover is an active/passive address reconnaissance tool, mainly developed for those wireless networks without dhcp server, when you are wardriving. It can be also used on hub/switched networks.

Built on top of libnet and libpcap, it can passively detect online hosts, or search for them, by actively sending arp requests, it can also be used to inspect your network arp traffic, or find network addresses using auto scan mode, which will scan for common local networks.

Amap is a next-generation tool for assistingnetwork penetration testing.
It performs fast and reliable application protocol detection, independant
on the TCP/UDP port they are being bound to.

BlackOp333 2008-06-06 17:46

Re: Pentesting with IT 2008 OS
 
Great!
Here is a program (a part of the aircrack suite that I got from the Backtrack 3 beta disk)
Could this be ported?
I can get you the .c too if you need it

poxika 2008-06-07 02:08

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by qwerty12 (Post 189022)
apt-get source kernel-source-rx-34 and you can compile your own.

I suppose that you meant to reply to my remark about iptables NAT ? I did try, without success. I tried as a module without success. If you actually tried and made it work, maybe you could post the method you use.

Benson 2008-06-07 02:35

Re: Pentesting with IT 2008 OS
 
You know the BT chipset in the N800 is capable of functioning as a BT sniffer?
http://darkircop.org/bt has relevant source code... I'm gonna try a build in the next week or so.

BlackOp333 2008-06-07 03:46

Re: Pentesting with IT 2008 OS
 
On that note, could carwhisperer be ported to OS 2008?
( http://trifinite.org/trifinite_stuff_carwhisperer.html )

qwerty12 2008-06-07 08:44

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by BlackOp333 (Post 189378)
Great!
Here is a program (a part of the aircrack suite that I got from the Backtrack 3 beta disk)
Could this be ported?
I can get you the .c too if you need it

Will do. (I would almost certainly need .c but I can use google ;P)

Quote:

Originally Posted by Benson (Post 189499)
You know the BT chipset in the N800 is capable of functioning as a BT sniffer?
http://darkircop.org/bt has relevant source code... I'm gonna try a build in the next week or so.

Quote:

Originally Posted by BlackOp333 (Post 189516)
On that note, could carwhisperer be ported to OS 2008?
( http://trifinite.org/trifinite_stuff_carwhisperer.html )

I actually planned to port some bluetooth stuff over (including carwhisper) . Benson has that darkircop site covered so I'll wait for that but I can port carwhisper (and a lot of other stuff) over.

I wish we had J2ME at least, http://java.xor.sk/?x=ftp_bt&en=1 I have < installed on all 3 of my phones and it's fun to "hack" phones. A bluejack app would be nice. Anyway, I'm finishing packaging my latest port so I'll upload here when done.

qwerty12 2008-06-07 09:02

Re: Pentesting with IT 2008 OS
 
2 Attachment(s)
fast, parallel, modular, login brute-forcer for network services

Medusa is intended to be a speedy, massively parallel, modular, login brute-forcer. The goal is to support as many services which allow remote authentication as possible. The author considers following items as some of the key features of this application:

* Thread-based parallel testing. Brute-force testing can be
performed against multiple hosts, users or passwords
concurrently.
* Flexible user input. Target information (host/user/password) can
be specified in a variety of ways. For example, each item can be
either a single entry or a file containing multiple entries.
Additionally, a combination file format allows the user to
refine their target listing.
* Modular design. Each service module exists as an
independent .mod file. This means that no modifications are
necessary to the core application in order to extend the
supported list of services for brute-forcing.

configure: ************************************************** *****
configure: Medusa Module Build Summary
configure:
configure: CVS Enabled
configure: FTP Enabled
configure: HTTP Enabled
configure: IMAP Enabled
configure: MSSQL Enabled
configure: MYSQL Enabled
configure: NCP ** Disabled **
configure: NNTP Enabled
configure: PCANYWHERE Enabled
configure: POP3 Enabled
configure: POSTGRES ** Disabled **
configure: REXEC Enabled
configure: RLOGIN Enabled
configure: RSH Enabled
configure: SMBNT Enabled
configure: SMTP-AUTH ** Disabled **
configure: SMTP-VRFY Enabled
configure: SNMP Enabled
configure: SSH Enabled
configure: SVN ** Disabled **
configure: TELNET Enabled
configure: VMAUTHD Enabled
configure: VNC Enabled
configure: WRAPPER Enabled
configure: WEB-FORM ** Disabled **
configure:
configure: If a module is unexpectedly marked as disabled, check
configure: above output and verify dependancies were satisfied.
configure:
configure: It should also be noted that, by default, not all of
configure: the modules are built. Incomplete modules or modules
configure: which have not been sufficiently tested may be
configure: disabled. To enable non-default modules, use the
configure: "--enable-module-MODULE_NAME" configure option.
configure: ************************************************** *****

(If you really need a module enabled, let me know. Except for the POSTGRES stuff, I ain't trying to set up no SQL on my scratchbox)

qwerty12 2008-06-07 09:35

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by BlackOp333 (Post 189378)
Great!
Here is a program (a part of the aircrack suite that I got from the Backtrack 3 beta disk)
Could this be ported?
I can get you the .c too if you need it

This one wouldn't compile usually so I did some makefile hacking muhahahaha.

easside-ng & wesside-ng

(this is literally eastside and westside of gangster fame :P)

Quote:

For you trivia buffs, who knows where the program name “wesside” came from? As it turns out, it comes from tupac the rapper (2Pac / Tupac Shakur).
http://www.mediafire.com/?1yj2cx9czuv

BlackOp333 2008-06-07 19:30

Re: Pentesting with IT 2008 OS
 
this is needed to run easside
Thanx for your work!

joepagiii 2008-06-07 19:50

Re: Pentesting with IT 2008 OS
 
dont have a clue why im following this thread... my town has a open wifi policy its neat however all the work being done...id like a bluejacker as well got it on my lifedrive ...kinda fun...

BlackOp333 2008-06-10 03:33

Re: Pentesting with IT 2008 OS
 
As the aircrack-ng on mulliner's repository is outdated (0.9.1)
Could this new version be ported?
(I'd do it myself but have no experience in scratchbox; is there a good tutorial out there?)
http://download.aircrack-ng.org/airc...1.0-rc1.tar.gz

qwerty12 2008-06-11 05:57

Re: Pentesting with IT 2008 OS
 
1 Attachment(s)
Quote:

Originally Posted by BlackOp333 (Post 189633)
this is needed to run easside
Thanx for your work!

buddy-ng.

w00t, I have to lengthen my message

qwerty12 2008-06-11 14:59

Re: Pentesting with IT 2008 OS
 
Quote:

Originally Posted by BlackOp333 (Post 190307)
As the aircrack-ng on mulliner's repository is outdated (0.9.1)
Could this new version be ported?
(I'd do it myself but have no experience in scratchbox; is there a good tutorial out there?)
http://download.aircrack-ng.org/airc...1.0-rc1.tar.gz

Why would I want to port this version ;P

Here is svn:
http://www.internettablettalk.com/fo...941#post190941

(Even newer :P)

BlackOp333 2008-06-11 15:11

Re: Pentesting with IT 2008 OS
 
Great!
This thread is turning out to be a great idea!
Thanx to qwerty)

qwerty12 2008-06-11 15:15

Re: Pentesting with IT 2008 OS
 
Np, thanks for making this thread, I've always wanted to know where the hacking tools are and I've seen some ones which I'd never heard of before :)


All times are GMT. The time now is 18:22.

vBulletin® Version 3.8.8