LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-29-2005, 08:45 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Rep: Reputation: 30
ettercap and ssl


Hi,
I really don't understand the redirect_command_on directive from etter.conf.
Why do I need it in order to sniff ssl traffic?

In my scenario, there are 3 hosts: source, destination and mitm host where I sniff ssl traffic between source and destination.

I want to arp poisen in order that all the ssl traffic between source and destination gets observed my mitm host. Mitm host has only one Ethernet interface which sniffs and then forwards the traffic to the real destination.

etter.conf:
redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"
redir_command_off = "iptables -t nat -D PREROUTING -i eth0 -p tcp --dport %port -j REDIRECT --to-port %rport"


I really don't understand the need for this kind of redirection and what %port and %rport are (based on my scenario).

Thank you for your help
 
Old 10-02-2005, 07:40 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I really don't understand the need for this kind of redirection and what %port and %rport are
You set up ARP poisoning pointing both hosts traffic to your box. Youre impersonating the host, so you also gotta mimick the services it runs (%port = service portnumber). If you didn't redirect traffic to (%rport = internal port Ettercap listens on) Ettercap it wouldn't be able to "read" it. If you don't redirect traffic after inspecting that would mean all responses between hosts would end up in the bitbucket.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ettercap vs. arpspoof kirmet Linux - Networking 0 11-03-2005 08:51 AM
AimSniff And Ettercap? ocdavi Linux - Networking 0 10-22-2005 02:58 PM
Ettercap 0.7.0 is it threat? dominant Linux - Security 1 08-13-2004 10:31 AM
ettercap NC 7 and MDK10 kvtournh Mandriva 0 07-26-2004 10:46 AM
Problem installing ettercap.6.b tobsai Linux - Software 0 09-26-2003 04:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration