LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-01-2012, 04:10 PM   #1
Showtime
LQ Newbie
 
Registered: May 2012
Posts: 3

Rep: Reputation: Disabled
Question Understanding how iptables (+arpspoof) works in a "soft" mitm attack


Hello,

i'm studying how a mitm attack works and i'm trying to figure out a few things. I'm trying to sniff packets of a third computer i have in my network, so in my linux machine (with a backtrack 5) i set up this commands:

echo 1 > /proc/sys/net/ipv4/ip_forward

then

iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port 8080

then i start arpspoof targeting on computer only with the -t option and giving the router as host.
The iptables command above is the same i use with sslstrip but this will be another question!

What i'm trying to understand is: how can i give to iptables a command that forward all the incoming
connection given by the arp poisoning to the host, make my linux pc acting like a trasparent gateway?
I would like to use this configuration to sniff all the traffic between the router and the attacked machine
with wireshark. For now i'd like to understand what i'm missing...
I remember than 10 years ago i was able to connect to an access point and sniff all the clients traffic,
but now this doesn't work anymore and i can't figure out what i'm missing. So in the meantime
i found as a solution, the arp spoofing, but it's not so silent as it was just sniffing with ethereal,
indeed if i attack all my home network some computers start to hang, while surfing the web.

My linux machine is a virtual machine done with vmware, running on osx Lion and i'm using an Alfa wus036nh as network card or a Dlink dwl122 which seems to work much better while arp poisoning!

Thank you in advance!
 
Old 05-03-2012, 03:05 AM   #2
rodrifra
Member
 
Registered: Mar 2007
Location: Spain
Distribution: Debian
Posts: 202

Rep: Reputation: 36
You might be interested in the next links:

http://openmaniak.com/ettercap_arp.php
http://arpspoof.sourceforge.net/
http://www.arpoison.net/
 
Old 05-05-2012, 06:13 PM   #3
Showtime
LQ Newbie
 
Registered: May 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by rodrifra View Post
Thanks!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
evdev/xorg help? USB mouse/kbd: 2.6.24="just works">2.6.25="unplug/replug to work". GrapefruiTgirl Linux - Hardware 4 12-13-2012 02:23 PM
Problem understanding IPtables "-d" param resetreset Linux - Networking 4 04-16-2012 03:46 AM
What is the difference btw. "soft nofile" and "hard nofile" by configuring open file? thomas2004ch Linux - Newbie 1 11-17-2009 05:33 AM
"Man in the middle attack" works against mix network? How to prevent? argh2xxx Linux - Security 6 09-28-2008 03:39 AM
IPTABLES: interface on "192.168.1.0/24" won't route clients from "10.65.0.0" zivota Linux - Networking 2 06-09-2008 01:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration