From charlesreid1

Revision as of 16:17, 25 August 2015 by Admin (talk | contribs)

MITM

Some cleanup on the Man in the Middle page.

Wired: Network tap, then ARP poisoning.

Wireless: Network tap (evil twin), then ARP poisoning.

Since I was successful at setting up the configuration for the Evil Twin router attack, but stumbled when it came to actually implementing the man in the middle attack,the idea here is to back up a step, remove the tricky Evil Twin configuration, and keep it simple.

Notes on setting up a wired network tap here:

Man in the Middle/Wired/Network Tap


Setup

Network Configuration

Caveman ASCII art of my network configuration:

--------------------         --------------
|     Router       |---------|  kronos    |
|                  |         | 10.0.0.19  |
|                  |         --------------
|                  |         --------------
|     10.0.0.1     |---------|   mars     |
|                  |         | 10.0.0.133 |
--------------------         --------------

Attacker/Sheep

In this scenario, the attacker Kronos 10.0.0.19 will be attacking the sheep Mars 10.0.0.133

Both are running Kali Linux.

The Attack

As described on the ARP Poisoning attack page, this attacks the lookup table that every router has that maps IP addresses to MAC addresses. If an attacker can modify entries in that table, they can receive all traffic intended for another party, make a connection to that party, and forward it along, tampering with the sheep's information.