This forum is in archive mode. You will not be able to post new content.

Author Topic: [question] Sniffing cleartext passwords on monitor interface.  (Read 2256 times)

0 Members and 1 Guest are viewing this topic.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
[question] Sniffing cleartext passwords on monitor interface.
« on: August 07, 2013, 06:46:21 AM »
Hello EZ,

Does anyone know of a tool that filters passwords from raw (live) packet captures.
I know I could use airodump-ng than use airdecap-ng to strip the 802.11 headers after finally giving it to dsniff.
If course one could write a bash to do all that in some hackish loopy way but im curious if anyone knows about a tool that does this on-the-fly.
Seen some stuff like irongeek's wall of shame but im curious if anyone knows about an other tool to do this directly?

Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Superflu0usRoot

  • /dev/null
  • *
  • Posts: 13
  • Cookies: 4
  • Pfft, Who Needs Root?
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #1 on: September 28, 2013, 01:45:06 PM »
I've seen a few programs that are built to specifically parse down information looking for specific passwords.

Cain has worked for me before, as well as some modules in wireshark.

What specific protocols are you wanting to get passwords from?
Got Root?
There's no Place Like 127.0.0.1

Offline Snayler

  • Baron
  • ****
  • Posts: 812
  • Cookies: 135
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #2 on: September 28, 2013, 02:37:58 PM »
I think you're looking for something like ettercap.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #3 on: September 28, 2013, 02:38:09 PM »
I've seen a few programs that are built to specifically parse down information looking for specific passwords.

Cain has worked for me before, as well as some modules in wireshark.

What specific protocols are you wanting to get passwords from?

Means I would need to use windows in some virtualbox draining my battery..
Not really practical.

In fact Ive been working on some code to do this.
Sniffing cleartext from a monitor interface and than doing some algo magic.
As for procotols, guess POP3, plain HTTP stuff like that.

@snayler, im aware of ettercap, again its not capable of handling 802.11 traffic directly.


*edit*
Im probably gonna release the tool here when its 'done'
Called it ClearNsnort.
Mainly targetted at sniffing cleartext , primairy goal to filter human written text.
« Last Edit: September 28, 2013, 02:46:36 PM by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #4 on: September 28, 2013, 05:08:45 PM »
I think you're looking for something like ettercap.


Ettercap does not sniff cleartext passwords.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #5 on: September 28, 2013, 05:51:18 PM »

Ettercap does not sniff cleartext passwords.

Quote
Password collectors for: TELNET, FTP, POP, IMAP, rlogin, SSH1, ICQ, SMB, MySQL, HTTP, NNTP, X11, Napster, IRC, RIP, BGP, SOCKS 5, IMAP 4, VNC, LDAP, NFS, SNMP, Half-Life, Quake 3, MSN, YMSG
Thats from wikipedia on ettercap :)
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Snayler

  • Baron
  • ****
  • Posts: 812
  • Cookies: 135
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #6 on: September 28, 2013, 05:52:27 PM »
Ettercap does not sniff cleartext passwords.
It doesn't? I was under the impression it did.

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #7 on: September 28, 2013, 06:09:17 PM »
Thats from wikipedia on ettercap :)
It doesn't? I was under the impression it did.
My judgment was from an experience with ettercap, depending on the authentication the site is using, you may or may not sniff clear text passwords, at my work, ettercap will sniff the ntlmv2 authentications sent by users connected on the network. However, ettercap comes with various plugins, one of them is smb_clear, which force the client to send passwords in clear text, but that depends also, this cloud crash the connection for all the users on the network.


At the end, ettercap cloud be the right tool an, or it cloud not be the right tool. May be you should try it out and decide for yourself.
« Last Edit: September 28, 2013, 06:13:20 PM by Axon »

Moiz

  • Guest
Re: [question] Sniffing cleartext passwords on monitor interface.
« Reply #8 on: September 28, 2013, 07:07:42 PM »
hello

just give this tool a try

http://code.google.com/p/subterfuge/

thanks

 



Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.