Re: [Full-Disclosure] Troubles with Wireless pentest

From: zcrips xrabbitz (zcrips_xrabbitz_at_hotmail.com)
Date: 06/22/04

  • Next message: Hugo Vazquez Carapez: "[Full-Disclosure] IFH-ADV-31338 Denial of service vulnerability in solar devices."
    To: filipe.almeida@gmail.com
    Date: Tue, 22 Jun 2004 10:04:14 +0100
    
    

    thanks
      i may have missed saying that
    the better part of the packets going trough the network had local
    destinations
    like lots of netbios queries, smb and the like with the local machines eth
    addr and ip addr.

    >From: Filipe Almeida <filipe.almeida@gmail.com>
    >To: sammy adedayo <sammyscity@yahoo.com>
    >CC: bugtraq@securityfocus.com, full-disclosure@lists.netsys.com,
    >vulnwatch@vulnwatch.org, zcrips_xrabbitz@hotmail.com
    >Subject: Re: [Full-Disclosure] Troubles with Wireless pentest
    >Date: Mon, 21 Jun 2004 20:00:55 +0100
    >
    >Hi,
    >First, you should get the mac address of the gateway. This is easy,
    >just look at the destination mac of the outgoing packets or the source
    >mac of incoming packets.
    >Then add a static arp entry of an ip of your subnet with that mac
    >address and use it as the gateway.
    >Traceroute or record route should get you the real ip of the gateway.
    >
    >Regards,
    >Filipe Almeida
    >http://community.sidestep.pt/~filipe/
    >
    >
    >----- Original Message -----
    >From: sammy adedayo <sammyscity@yahoo.com>
    >Date: Mon, 21 Jun 2004 10:41:28 -0700 (PDT)
    >Subject: [Full-Disclosure] Troubles with Wireless pentest
    >To: bugtraq@securityfocus.com, full-disclosure@lists.netsys.com,
    >vulnwatch@vulnwatch.org
    >Cc: zcrips_xrabbitz@hotmail.com
    >
    >
    >
    >
    >
    >A little help would be appreciated on this.
    >
    >
    >
    >
    >
    > A few problems occurred during a wireless pentest I am
    >presently undertaking. First a foundation,
    >
    >
    >1) The pentest was a zero knowledge kind, no information was given,
    >in fact we were forbidden to ask for help from any of the staffs
    >
    >
    >These I found during the first day.
    >
    >
    >2) The network had a weak point = its wireless network.
    >
    >
    >3) The wireless network was encrypted but with the weak wep and for a
    >large corporation the data captured was enough to get the key
    >
    >
    >4) The network in focus is quite large with multiple subnets and lots
    >of �firewalls�
    >
    >
    >These I did.
    >
    >
    >5) Using kismet I sniffed a whole lot of packets. And decoded them
    >with the found wep key
    >
    >
    >6) Then using my conventional ettercap and ethereal I looked through
    >the packets.
    >
    >
    >Now The Problem.
    >
    >
    >7) I tried to connect to the net work
    >
    >
    >8) I used a nice ip to match those on the network
    >
    >
    >9) Then I used ettercap to try and passively find the gateway but could not
    >
    >
    >10) I used etterape to watch the packet flow but I could not figure
    >out the gateway from all that traffic
    >
    >
    >HELP
    >
    >
    >HOW CAN I GET THE GATEWAY FOR THE WIRELESS NETWORK AND IS THERE ANY
    >WAY I COULD ROUTE PACKETS TO / CONNECT TO/ SCAN THE REST OF THE
    >MACHINES ON THE NETWORK WITH OUT THE GATEWAYS ADDRESS.
    >
    >
    >
    >
    >
    >OR IS THERE A BETTER WAY TO DO THE WHOLE PENTEST?
    >
    >
    >Pls help would be gladly appreciated.
    >
    >
    >Any ideas are welcome. THANKS�
    >
    >
    >
    >
    >
    >Zippers crips
    >
    >
    >
    >
    >
    >The Zcrips Inc
    >
    >
    >-----------------------------------------------------------------
    >
    >
    >a man is only limited by his imaginative abilities
    >
    >
    >
    >
    >
    > ________________________________
    >Do you Yahoo!?
    >
    >Yahoo! Mail - You care about security. So do we.

    _________________________________________________________________
    MSN 8 with e-mail virus protection service: 2 months FREE*
    http://join.msn.com/?page=features/virus

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Hugo Vazquez Carapez: "[Full-Disclosure] IFH-ADV-31338 Denial of service vulnerability in solar devices."

    Relevant Pages

    • Re: Cant access secure Web pages
      ... and which need to be contacted via the Default Gateway. ... The Default Gateway being the software process that does the network ... Gateway (as set up by your ISP's DHCP packet to the router), ... me so I can send it directly (to the MAC address discovered by ARP). ...
      (uk.comp.sys.mac)
    • Re: Convention User Woas
      ... gateway, they're not able to reach off the LAN either, as most operating ... Where they st00pid enough to not spoof the MAC address as well? ... If this is a _wired_ network, you can set your switch so that it knows on ... with some APs you can set them so there is no client to client traffic ...
      (comp.dcom.lans.ethernet)
    • RE: ARP Spoof Question
      ... Hardware MAC addresses are supposed to be globally unique. ... If you have duplicate MAC addresses on a shared-media network, ... > spoofed ARP packets to receive packets but have been unable to locate ... > my switch table. ...
      (Security-Basics)
    • RE: TCP/IP Stack Hardening
      ... Crappy network performance and file transfer timeouts but boy ... frag" packets. ... Disabling PMTU discovery reduces ALL packets to 576 bytes or ... may need to redirect traffic to a different gateway (e.g. Internet ...
      (Focus-Microsoft)
    • Re: tcpip gateway question
      ... to also sit on the University network 137.222.0.0/16. ... connect to any node with ssh and ping any local node from any node ... packets transmitted, 4 packets received, 0% packet loss ... connectivity to the default gateway on the University side. ...
      (comp.os.vms)