Notices


Reply
Thread Tools
Posts: 111 | Thanked: 87 times | Joined on Jan 2010 @ Plovdiv, Bulgaria
#241
Don't abuse the script on foreign networks. If it was your network you would of known if those numbers were a password.

EDIT:

late by 3 seconds
__________________
http://pcsci3nce.info
 
Posts: 83 | Thanked: 142 times | Joined on Jun 2011 @ Paris, France
#242
Originally Posted by Unhuman View Post
Don't abuse the script on foreign networks. If it was your network you would have known if those numbers were a password.

EDIT:

late by 3 <i>minutes</i>
<useless post>Mouahahaha*, beat ya !</useless post>

*French evil laugh
__________________
http://comax.fr/
"I like to dissect girls. Did you know I am utterly insane ?"

Last edited by comaX; 2011-06-30 at 15:06.
 
Posts: 1,335 | Thanked: 3,931 times | Joined on Jul 2010 @ Brittany, France
#243
Damn frog-eater!*

Still no success at trying Yamas there. I have no idea of what is the problem in my case, since I don't have all the error logs that Price reported, just the one I quoted above.

I can't try it again for the moment 'cause I'm at work, and attacking the wifi of the laboratory/university would be a suicide I guess.



* J'en suis un moi-même. :[

Last edited by Kabouik; 2011-06-30 at 15:16.
 
AgogData's Avatar
Posts: 870 | Thanked: 133 times | Joined on Aug 2010
#244
Originally Posted by comaX View Post
Hmm... You sir are a bad student ! Since you're assuming it may be the password, it means you don't know it. If you don't know it, it's not yours. I'm sorry, but I won't help you for that.
Here's just a hint : we are parsing the log.

You should use the script on your own connection and then get log into a maximum of sites to know what the output should look like.

The saving location is just a variable now, so you can change it to whatever suits you Saturn used this location because of some problem with MyDocs not being always available or something.
yes its not my network, its not illegal here but its rude
anyway i didn't mean any harm to the...victim, just using my n900's ability
 
Posts: 102 | Thanked: 23 times | Joined on Nov 2009 @ Finland
#245
i have this "egrep: bad regex" error too every time i try it. i have all depencies installed, no matter what website i try i allways get this error
 
Posts: 1,163 | Thanked: 1,873 times | Joined on Feb 2011 @ The Netherlands
#246
Runned the attack this day and worked as it should, except that the victim pc got sometimes a page with only the letters:

ht

then reload gives a page with:

hmtl layout code of that page without images

another reload gives:

The actual page, with good layout =D

On the phone side everything works. Gonna need to find my flashdrive with backtrack again, and test if I get these pages when running from backtrack also. Last time I tried a mitm-attack this wonderful script wasn't available :P Thanks for making me this easy, ComaX
 
Posts: 102 | Thanked: 23 times | Joined on Nov 2009 @ Finland
#247
rebooted the n900, now i get following in the password window:

BusyBox v1.18.5 (Debian 1.18.5power1) multi-call binary.

No help available.

it flashes every now and then, the grep error dissappeared but i stil get no other output than this..
 
Posts: 83 | Thanked: 142 times | Joined on Jun 2011 @ Paris, France
#248
Originally Posted by AgogData View Post
yes its not my network, its not illegal here but its rude
anyway i didn't mean any harm to the...victim, just using my n900's ability
Well, I don't know where you live, but I'd bet my *** it is pretty much illegal ^^ Anyway, you do whatever you want, it's not like we're the cops or about to call them !

Originally Posted by teemui View Post
rebooted the n900, now i get following in the password window:

BusyBox v1.18.5 (Debian 1.18.5power1) multi-call binary.

No help available.

it flashes every now and then, the grep error dissappeared but i stil get no other output than this..
So the problem definitively comes from some error at an installation/package level... Since I do not have the N900 I can't help much, but I'm sure others members will

Originally Posted by mr_pingu View Post
Runned the attack this day and worked as it should, except that the victim pc got sometimes a page with only the letters:

ht

then reload gives a page with:

hmtl layout code of that page without images

another reload gives:

The actual page, with good layout =D

On the phone side everything works. Gonna need to find my flashdrive with backtrack again, and test if I get these pages when running from backtrack also. Last time I tried a mitm-attack this wonderful script wasn't available :P Thanks for making me this easy, ComaX
Yeahp, not my fault ! That's sslstrip's work... I mean, sometimes it will just be fine, but most of the time you'll have to reload once. Let's hope that will be fixed in sslstrip 1.0.
About your BT drive, the original script will ony work on BT5. The BT4r2 version is still available though.

Originally Posted by Kabouik View Post
Damn frog-eater!*

Still no success at trying Yamas there. I have no idea of what is the problem in my case, since I don't have all the error logs that Price reported, just the one I quoted above.

I can't try it again for the moment 'cause I'm at work, and attacking the wifi of the laboratory/university would be a suicide I guess.



* J'en suis un moi-même. :[
Yeah, no. You can do that, but we don't want to know ! And yes, that would be suicide ! Maybe even for your phone if there is a lot of traffic going on...
Don't hesitate to send me your logs (edited if you want, but I could care less about your/their () passwords) by mail and any output you have. You can even write them in French
For the small-talk part, I actually wrote most of the structure of the script while at university. Never tested it there though, since you need you name and pass to connect to the network... So matching my name to some weird-*** ARPs wouldn't have been too much of a hassle.
__________________
http://comax.fr/
"I like to dissect girls. Did you know I am utterly insane ?"

Last edited by comaX; 2011-06-30 at 17:06.
 

The Following User Says Thank You to comaX For This Useful Post:
Posts: 1,163 | Thanked: 1,873 times | Joined on Feb 2011 @ The Netherlands
#249
Originally Posted by comaX View Post


Yeahp, not my fault ! That's sslstrip's work... I mean, sometimes it will just be fine, but most of the time you'll have to reload once. Let's hope that will be fixed in sslstrip 1.0.
About your BT drive, the original script will ony work on BT5. The BT4r2 version is still available though.

Don't worry I have a strange mood and am installing bt5 on local drive

Edit: Yeah, I f###ed up, grub rescue unknown filesystem yeah :d
 
Posts: 102 | Thanked: 23 times | Joined on Nov 2009 @ Finland
#250
Finally i got this to work.. if someone still have same issues i had, in this order what i did:
reinstalled yamas
reinstalled ettercap
reinstalled sslstrip
im not sure if it messed everything, but first time i installed first ettercap then sslstrip and last yamas..
Thank you all, specially comaX
 
Reply

Tags
pentesting, tester of pens


 
Forum Jump


All times are GMT. The time now is 10:50.