4 ms·
Yes, Ettercap, by default, is in promiscuous mode. It does quite a bit more than just ARP poisoning though, it can also do DHCP and ICMP spoofing among others.
by meinhimmel 16y ago
Yes, Ettercap, by default, is in promiscuous mode. It does quite a bit more than just ARP poisoning though, it can also do DHCP and ICMP spoofing among others.
Here's the man page: http://linux.die.net/man/8/ettercap http://linux.die.net/man/8/ettercap
- StavrosK 16y agoI meant set the router in a sort of promiscuous mode (i.e. make it send you all the packets, regardless of their original destination), not the adapter. These types of poisoning are very useful, but they're not what you need for Firesheep. With a poisoning attack, you override the packet's destination and it's up to you to send (it's an active attack). Firesheep just monitors passively, which is why I was wondering if it worked anywhere. I agree with you, I'm just saying that the type of passive monitoring Firesheep does only works on unsecured wifi networks and is, thus, not very useful.
- meinhimmel 16y agoWell, setting your adapter into promiscuous mode will allow you to capture all the packets. By using Ettercap though to put your adapter into promiscuous mode, it will handle the packet forwarding for you. Therefore, you can use Firesheep to monitor the entire network pretty easily. From what I've seen it should capture them from everyone on the network, since Firesheep is simply capturing packets from whatever the adapter sees over TCP port 80. I haven't tried that yet, so you might be right. Also, an attacker can simply use SSLStrip and get the cleartext passwords for online services anyway. This isn't anything novel, since there have been plenty of attacks that allow you to session hijack rather easily (i.e. hamster). You can even simply monitor in Wireshark and manually enter the session information into your cookies.