<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ArLUG (Arad Linux Users Group) &#187; Securitate</title>
	<atom:link href="http://www.arlug.ro/tag/securitate/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.arlug.ro</link>
	<description>ArLUG (Arad Linux Users Group)</description>
	<lastBuildDate>Sun, 11 Dec 2011 20:29:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
		<item>
		<title>ARP poisoning</title>
		<link>http://www.arlug.ro/2010/01/arp-poisoning/</link>
		<comments>http://www.arlug.ro/2010/01/arp-poisoning/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 12:23:54 +0000</pubDate>
		<dc:creator>Silviu Silaghi</dc:creator>
				<category><![CDATA[Educaţie]]></category>
		<category><![CDATA[Securitate]]></category>
		<category><![CDATA[arp poison]]></category>
		<category><![CDATA[arp spoofing]]></category>

		<guid isPermaLink="false">http://www.arlug.ro/?p=678</guid>
		<description><![CDATA[Un articol de hacking, din care se poate învăţa câte ceva despre funcţionalitatea şi/sau securitatea reţelelor informatice. Informaţiile conţinute în acest articol sunt de natura strict informaţională şi recomand reproducerea lor doar in laborator sau alte medi de test sigure. Articolul este luat şi tradus de pe situl http://openmaniak.com/ un site bunicel în materie de [...]]]></description>
			<content:encoded><![CDATA[<p>Un articol de hacking, din care se poate învăţa câte ceva despre funcţionalitatea şi/sau securitatea reţelelor informatice. <span style="color: #ff0000;">Informaţiile conţinute în acest articol sunt de natura strict informaţională şi recomand reproducerea lor doar in laborator sau alte medi de test sigure</span>.</p>
<p>Articolul este luat şi tradus de pe situl <a href="http://openmaniak.com/" target="_blank">http://openmaniak.com/</a> un site bunicel în materie de securitate.</p>
<p>Articolul tradus este acesta:<a href="http://openmaniak.com/ettercap_arp.php" target="_blank">http://openmaniak.com/ettercap_arp.php</a>.</p>
<p>În acest tutorial, maşina noastră ettercap va juca rolul de &#8220;omul din mijloc&#8221; (man in the middle), după un atac de spoofing ARP.</p>
<p>Diagrama(<a href="http://openmaniak.com/ettercap.php#diagram" target="_blank">http://openmaniak.com/ettercap.php#diagram</a>) scenariului este disponibilă în pagina de introducere ettercap.<br />
Primul lucru de facut este de a stabili o adresă IP pe maşina dvs. ettercap în aceeaşi subreţea cu masina pe care doriţi să faceţi <em>poison</em>. Pentru tutorialul noastu adresa IP 192.168.1.100 este utilizată.<br />
A se vedea de tutorialul de netwoking(<a href="http://openmaniak.com/networking.php" target="_blank">http://openmaniak.com/networking.php</a>) pentru explicaţii detaliate despre cum să setaţi o adresă de IP pe Linux.</p>
<p>Ca un memento, ettercap va avea nevoie de acces root pentru a fi lansat, apoi va putea fi &#8220;suportat&#8221; de utilizatorul <em>nobody</em>.</p>
<div>1.ARP spoofing.</div>
<div>- Deschide Ettercap in mod grafic</div>
<p><strong>#ettercap -G</strong></p>
<p><strong><br />
</strong><a href="http://openmaniak.com/ettercap/ettercap_step01.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_step01_p.png" alt="openmaniak ettercap" /></a></p>
<p>- Selectează &#8220;sniff mode&#8221;<br />
<strong> Sniff -&gt; Unified sniffing</strong></p>
<p><strong><br />
</strong><a href="http://openmaniak.com/ettercap/ettercap_step02.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_step02_p.png" alt="openmaniak ettercap man in the middle attack sniff united sniffing" /></a><br />
<a href="http://openmaniak.com/ettercap/ettercap_step03.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_step03_p.png" alt="openmaniak ettercap" /></a></p>
<p>Scanează gazda din subnetul tau<br />
<strong>Hosts -&gt; Scan for hosts </strong><br />
Scanearea campului de adrese depinde de setările făcute anterior pe placa de reţea<br />
<a href="http://openmaniak.com/ettercap/ettercap_step04.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_step04_p.png" alt="openmaniak ettercap man in the middle attack " /></a><br />
<a href="http://openmaniak.com/ettercap/ettercap_step05.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_step05_p.png" alt="openmaniak ettercap  man in the middle attack sniff united sniffing" /></a></p>
<p>Vezi adresele IP şi MAC a calculatoareleor din subreţea.<br />
<a href="http://openmaniak.com/ettercap/ettercap_hostlist01.png" target="_blank"><img class="alignnone" src="http://openmaniak.com/ettercap/ettercap_hostlist01_p.png" alt="openmaniak ettercap man in the middle attack " width="300" height="230" /></a></p>
<p>Selectaţi maşinile pentru poison<br />
Am ales sa facem ARP poison doar pentru un sistem Windows şi routerul 192.168.1.2 192.168.1.1.<br />
Selectaţi linia ce conţine 192.168.1.1 şi faceţi clic pe butonul &#8220;Target 1&#8243;.<br />
Selectaţi linia ce conţine 192.168.1.2 şi faceţi clic pe butonul &#8220;Target 2&#8243;.<br />
Dacă nu selectaţi nici o maşină ca ţintă, toate maşinile din subreţea vor fi ARP atacate.<br />
<a href="http://openmaniak.com/ettercap/ettercap_hostlist02.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_hostlist02_p.png" alt="openmaniak ettercap man in the middle attack" /></a></p>
<p>Verifică ţintele<br />
<a href="http://openmaniak.com/ettercap/ettercap_target01.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_target01_p.png" alt="openmaniak ettercap man in the middle attack" /></a><br />
<a href="http://openmaniak.com/ettercap/ettercap_target02.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_target02_p.png" alt="man in the middle attack openmaniak ettercap" /></a></p>
<p>Începe ARP Poisoning<br />
<strong>Start -&gt; Start sniffing </strong><br />
<a href="http://openmaniak.com/ettercap/ettercap_start_sniff.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_start_sniff_p.png" alt="man in the middle attack openmaniak ettercap" /></a><br />
<a name="arp_traffic"><br />
</a></p>
<p><a name="arp_traffic"> &#8211; ARP TRAFFIC</a>:</p>
<p>Pe un sistem Windows, cu ajutorul Wireshark, putem compara traficul ARP înainte şi după atac:</p>
<table>
<tbody>
<tr>
<td>192.168.1.1<br />
192.168.1.2<br />
192.168.1.100</td>
<td>(Router)<br />
(Windows)<br />
(Pirate)</td>
<td>11:22:33:44:11:11<br />
11:22:33:44:55:66<br />
11:22:33:44:99:99</td>
</tr>
</tbody>
</table>
<p><em>Înainte de atac</em><br />
Înainte de a începe să comunice, router-ul şi Windows-ul trimit un broadcast  ARP(http://en.wikipedia.org/wiki/Broadcasting_%28networks%29) pentru aşi găsi adresa fiecăruia de MAC.</p>
<table>
<tbody>
<tr>
<td>No<br />
1<br />
2<br />
3<br />
4</td>
<td></td>
<td>Source<br />
11:22:33:44:55:66<br />
11:22:33:44:11:11<br />
11:22:33:44:11:11<br />
11:22:33:44:55:66</td>
<td></td>
<td>Destination<br />
11:22:33:44:11:11<br />
11:22:33:44:55:66<br />
11:22:33:44:55:66<br />
11:22:33:44:11:11</td>
<td></td>
<td>Prot<br />
ARP<br />
ARP<br />
ARP<br />
ARP</td>
<td></td>
<td>Info<br />
who has 192.168.1.1? Tell 192.168.1.2<br />
192.168.1.1 is at 11:22:33:44:11:11<br />
who has 192.168.1.2? Tell 192.168.1.1<br />
192.168.1.2 is at 11:22:33:44:55:66</td>
</tr>
</tbody>
</table>
<p><em>După otrăvire</em><br />
Cererea routerului de ARP brodcast este similară ca pentru un Windows.<br />
Diferenţa dintre cele două etape vine de la faptul că nu există nici o cerere provenind de la Windows (192.168.1.2) pentru a găsi adresa MAC asociată la router (192.168.1.1), deoarece atacatorul trimite continuu pachete ARP spunândui maşinii Windows ca 192.168 .1.1 este asociat cu propria adresa MAC (11:22:33:44:99:99) în loc de adresa de router-MAC (11:22:33:44:11:11).</p>
<table>
<tbody>
<tr>
<td>No<br />
1<br />
2<br />
3<br />
4</td>
<td></td>
<td>Source<br />
11:22:33:44:11:11<br />
11:22:33:44:55:66<br />
11:22:33:44:99:99<br />
11:22:33:44:99:99</td>
<td></td>
<td>Destination<br />
11:22:33:44:55:66<br />
11:22:33:44:11:11<br />
11:22:33:44:55:66<br />
11:22:33:44:55:66</td>
<td></td>
<td>Prot<br />
ARP<br />
ARP<br />
ARP<br />
ARP</td>
<td></td>
<td>Info<br />
who has 192.168.1.2? Tell 192.168.1.1<br />
192.168.1.2 is at 11:22:33:44:55:66<br />
<span style="color: red;">192.168.1.1 is at 11:22:33:44:99:99<br />
<span style="color: red;">192.168.1.1 is at 11:22:33:44:99:99 </span></span></td>
</tr>
</tbody>
</table>
<p>- TABELE ARP:<br />
Dacă ne uităm la tabela ARP a routerului şi a Windowsului, vedem că maşina Linux cu ettercup a &#8220;otravit&#8221; tabela lor de ARP şi a înlocuit  adresa MAC a routerului si a Windowsului cu propria lui adresă MAC.<br />
Acest lucru înseamnă că pachetele trimise între maşina Windows şi router vor tranzita reţeaua prin maşina cu ettercap.<br />
Să vedem dacă am &#8220;otrăvit&#8221; cu succes tabela de ARP din router şi Windows:</p>
<table>
<tbody>
<tr>
<td>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</td>
<td><img src="http://openmaniak.com/ettercap/ettercap_windows.gif" alt="" /></td>
<td>Windows machine 192.168.1.2</td>
<td>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</td>
</tr>
</tbody>
</table>
<p>Din Windows:<br />
<strong>Start -&gt; Run -&gt; cmd </strong><br />
C:\Documents and Settings\administrator&gt;<strong>arp -a<br />
</strong>Interface &lt;numele interfeţei&gt;: 192.168.1.2 &#8212; 0&#215;2</p>
<table>
<tbody>
<tr>
<td>Internet Address<br />
192.168.1.1<br />
192.168.1.100</td>
<td>Physical Address<br />
11-22-33-44-11-11<br />
11-22-33-44-99-99</td>
<td>Type<br />
dynamic<br />
dynamic</td>
</tr>
</tbody>
</table>
<p><img src="http://openmaniak.com/image/arrow_down.gif" alt="arrow blue" /><br />
Interface &lt;numele interfeţei&gt;: 192.168.1.2 &#8212; 0&#215;2</p>
<table>
<tbody>
<tr>
<td>Internet Address<br />
192.168.1.1<br />
192.168.1.100</td>
<td>Physical Address<br />
<span style="color: red;">11-22-33-44-99-99</span><br />
11-22-33-44-99-99</td>
<td>Type<br />
dynamic<br />
dynamic</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</td>
<td><img src="http://openmaniak.com/ettercap/ettercap_machine.gif" alt="" /></td>
<td>Linux machine 192.168.1.100</td>
<td>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</td>
</tr>
</tbody>
</table>
<p><strong>#arp -a</strong></p>
<p><strong> </strong></p>
<table>
<tbody>
<tr>
<td>?<br />
?</td>
<td>(192.168.1.1)<br />
(192.168.1.2)</td>
<td>at<br />
at</td>
<td>11:22:33:44:11:11<br />
11:22:33:44:55:66</td>
<td>[ether]<br />
[ether]</td>
<td>on<br />
on</td>
<td>eth0<br />
eth0</td>
</tr>
</tbody>
</table>
<table>
<tbody>
<tr>
<td>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</td>
<td><img src="http://openmaniak.com/ettercap/ettercap_router.gif" alt="router openmaniak cisco" /></td>
<td>Router 192.168.1.1</td>
<td>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</td>
</tr>
</tbody>
</table>
<p><strong>&gt;show arp</strong></p>
<p><strong> </strong></p>
<table>
<tbody>
<tr>
<td>Protocol<br />
Internet<br />
Internet</td>
<td></td>
<td>Address<br />
192.168.1.2<br />
192.168.1.100</td>
<td></td>
<td>Age (min)<br />
194<br />
128</td>
<td></td>
<td>Hardware Addr<br />
1122.3344.5566<br />
1122.3344.9999</td>
<td></td>
<td>Type<br />
ARPA<br />
ARPA</td>
<td></td>
<td>interface<br />
FastEthernet0/0<br />
FastEthernet0/0</td>
</tr>
</tbody>
</table>
<p><img src="http://openmaniak.com/image/arrow_down.gif" alt="arrow blue" /></p>
<table>
<tbody>
<tr>
<td>Protocol<br />
Internet<br />
Internet</td>
<td></td>
<td>Address<br />
192.168.1.2<br />
192.168.1.100</td>
<td></td>
<td>Age (min)<br />
194<br />
128</td>
<td></td>
<td>Hardware Addr<br />
<span style="color: red;">1122.3344.9999</span><br />
1122.3344.9999</td>
<td></td>
<td>Type<br />
ARPA<br />
ARPA</td>
<td></td>
<td>interface<br />
FastEthernet0/0<br />
FastEthernet0/0</td>
</tr>
</tbody>
</table>
<p>Dacă ai Netscreen (Juniper), foloseşte comnda:<br />
<strong>&gt;get arp<br />
</strong>Pe un router Vyatta(http://openmaniak.com/vyatta.php)<br />
<strong>&gt;show arp</strong></p>
<p>- OPRIREA ARP spoofing:</p>
<p><a href="http://openmaniak.com/ettercap/ettercap_stop_arp.png" target="_blank"><img src="http://openmaniak.com/ettercap/ettercap_stop_arp_p.png" alt="openmaniak ettercap" /></a></p>
<p>Ettercap este destul de eficient. După atac, acesta va reasigna ARP-ul victimelor. Cu alte cuvinte, victimele vor primi din nou setările corecte.<br />
Daca nu îşi revine singur în câteva minute, curăţaţi cache-ul ARP</p>
<p>Pe Windows:</p>
<table>
<tbody>
<tr>
<td>C:\Documents and Settings\admin&gt;<strong>arp -d *</strong></td>
</tr>
</tbody>
</table>
<p>Pe un Linux:</p>
<table>
<tbody>
<tr>
<td>#<strong>arp -d</strong> <em>ip_address</em></td>
</tr>
</tbody>
</table>
<p>Pe un router Cisco:</p>
<p>#<strong>clear arp-cache</strong></p>
<blockquote><p><strong><br />
</strong></p></blockquote>
<p>Tradus de la <a href="http://openmaniak.com/ettercap_arp.php" target="_blank">http://openmaniak.com/ettercap_arp.php</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.arlug.ro/2010/01/arp-poisoning/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

