RE: Cain a& Abel Question

From: Cushing, David (David.Cushing_at_hitachisoftware.com)
Date: 05/21/03

  • Next message: Alfred Huger: "SecurityFocus Article Announcement"
    Date: Wed, 21 May 2003 14:15:21 -0400
    To: <pjacob@ftmc.com>, <pen-test@securityfocus.com>
    

    Pete,

    What you are seeing is the result of a "man in the middle" style attack rather than a decoding of your SSL connection to the bank.

    C&A is intercepting and forwarding your traffic due to the ARP poisoning. Your browser negotiates an SSL connection with C&A. C&A negotiates another SSL connection to the bank. Then C&A is able to see all traffic in plaintext as it passes it along.

    Browser <--ssl--> C&A (plaintext) <--ssl--> Bank

    The program is not able to generate a proper certificate to hand your browser, though. It is self signed and will not be trusted by your browser. An alert should have popped up when you opened the page. Did it?

    Cain info: http://www.oxid.it/cain_faq.html
    MiM info: http://www.sans.org/rr/threats/man_in_the_middle.php

    --
    David
    > -----Original Message-----
    > I was reading thru the list and decided to give Cain & Abel a try...
    > it is a really powerful tool, I do have a question, I was running it
    > using the ARP poisoning from one of my test machines to my internet
    > gateway.. (Cisco 3600 series) I logged into my On-line 
    > banking account,
    > which is an SSL connection, and Cain & Abel picked up my username and
    > passsword as "Clear text"... I guess I am confused about this...
    > when I goto the site, it is an SSL site,it appears that the entire
    > session is SSL, and Cain & Abel is not doing any sort of 
    > "Cracking" and
    > if the software "Cain & Abel" is doing
    > some sort of sniffing, wouldn't it be encrypted via SSL?
     
    ---------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies 
    that are enforced to protect WLANs from known vulnerabilities and threats. 
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.
    To get your FREE white paper visit us at:    
    http://www.securityfocus.com/AirDefense-pen-test
    ----------------------------------------------------------------------------
    

  • Next message: Alfred Huger: "SecurityFocus Article Announcement"

    Relevant Pages

    • Cain a& Abel Question
      ... I was reading thru the list and decided to give Cain & Abel a try... ... when I goto the site, it is an SSL site,it appears that the entire ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Pen-Test)
    • RE: Cain a& Abel Question
      ... Subject: Cain a& Abel Question ... What you are seeing is the result of a "man in the middle" style attack rather than a decoding of your SSL connection to the bank. ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Pen-Test)
    • RE: Cain a& Abel Question
      ... Subject: Cain a& Abel Question ... Your browser negotiates an SSL connection with C&A. C&A negotiates ... that are enforced to protect WLANs from known vulnerabilities and threats. ...
      (Pen-Test)
    • Re: Preventing tunnels through HTTPS proxies
      ... Alternatively playing a man-in-the-middle on the proxy, ... but also the matter of the stuff in SSL certificate matching the ... look up the SSL handshake procedure) you were able to distinguish SSL ... How can you tell HTTP traffic over SSL connection from any other ...
      (Security-Basics)
    • Re: Can SSL sessions be compromised?
      ... us to use their computers for internet access to our headquarters. ... etc) attachments using webmail during these SSL sessions. ... Depends on the endpoints of the SSL connection. ... proxy server, then be aware that they can read everything. ...
      (comp.security.misc)