RES: PPPOE password sniffing





-----Mensagem original-----
De: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] Em
nome de alexpheno@xxxxxxxxx
Enviada em: sábado, 27 de janeiro de 2007 18:43
Para: pen-test@xxxxxxxxxxxxxxxxx
Assunto: Re: PPPOE password sniffing

If you're using PAP as an authentication scheme you must look into the
packets that follow the PPPOE session, after you've found a PPPOE
access concentrator a PPP session is established. You must look for a
packet that is sent by the authenticating terminal (in this case your
computer) to the concentrator. Try to do a wireshark capture and
apply this filter rule "pap and eth.src==XX:XX:XX:XX:XX:XX", and
replace the x part with the terminal's mac address. If a frame matches
the filter it should contain the user and password in the payload.

Check out RFC1334 for more info.
--
Alex Nedelcu
CCNA, SNRS, CSVPN

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=70160000
0008bOW
------------------------------------------------------------------------

Attachment: smime.p7s
Description: S/MIME cryptographic signature



Relevant Pages

  • Re: Restarting ADSL Connection Problem
    ... >> For PPPoE the MTU should be around 48 bytes larger than the MSS value. ... Ping some internet server and stipulate ... In the first example a payload of 1473 bytes is too large: ... packets transmitted, 0 packets received, 100.0% packet loss ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Networking Puzzle
    ... I run PPPoE on rl0 which gives me an static IP address (lets call ... Sysctl is set to forward packets, and machines on the LAN with public ...
    (freebsd-current)
  • 3.6 pppoe setup fails - config/debug info incl >
    ... with my pppoe setup? ... ppp ON iDSRDL> quit all ... packets transmitted, 5 packets received, 0.0% packet loss ... block drop out log-all quick inet6 all ...
    (comp.unix.bsd.openbsd.misc)
  • Re: PPPoE misbehaving?
    ... vendor = 'Atheros Communications Inc.' ... the card is working and functioning properly - I am 99% ... sure it is a problem related with PPPoEd, or something in regards to PPPoE ... > M>> the packets without problems... ...
    (freebsd-questions)
  • Re: PPPoE on Linux box
    ... >> Specifics depend on the distro and the version of the distro you're ... PPPoE should be in Debian's documentation somewhere. ... wrapper is removed before the packets get thrown on the backbone. ... required a specific string in the Hostname field of the DHCP request ...
    (comp.os.linux.misc)