LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-31-2006, 07:00 AM   #1
birdee
LQ Newbie
 
Registered: Jul 2005
Posts: 6

Rep: Reputation: 0
Hijacking sessions using HUNT


Dear all,

I am trying to understand hijacking a tcp session.

I use hunt 1.5 for debian in my own lab of 3 pcs connected using a hub and I cannot list any active session even though....

1. I have managed to arpspoof the 2 pcs with the mac address of my attacking pc even though the hunt screen was telling my that the arpspoofing failed. I confirm from tcpdump that I am actually seeing arp reply for my 2 pcs having the same mac address of my attacking pc.

2. Assuming that the arpspoof is successful. Then why i am not able to list any active session between the 2 pcs ? I have tried to initate a telnet connection from one pc but the hunt program is still not showing any active connection.

3. I am sure u gurus out there, may have played with hunt before and can some kind soul tell me what did i do wrong or maybe even whipped out a tutorial on this...

regards,birdee
 
Old 05-31-2006, 09:46 AM   #2
sopiaz57
Member
 
Registered: Apr 2003
Distribution: RH 8
Posts: 246

Rep: Reputation: 30
tried

I spent 20 minutes playing with this and reading the man pages, its not the most clear utilitiy is it? Have you had any luck?

I setup a simple spoof with 1 connection between my 1st machine and my 2nd machine (running telnet service)
then when i tried to watch this connection is said no connections active.

isnt there a better way to watch connections?
 
Old 06-01-2006, 08:23 PM   #3
birdee
LQ Newbie
 
Registered: Jul 2005
Posts: 6

Original Poster
Rep: Reputation: 0
Hi,

Thanks for yr reply. I have no idea why hunt is showing no active connection. I did a little sniffing(TCPDUMP) and I can see my own telnet traffic.Since TCPDUMP can pick up the telnet traffic,then why is hunt no able to see this active connection..

Anyone ???

r/birdee
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
hijacking with Hunt jgomes Linux - Security 1 06-03-2005 05:46 PM
Hijacking jgomes Linux - Software 1 06-01-2005 12:24 PM
hijacking posts titanium_geek LQ Suggestions & Feedback 2 10-13-2004 07:31 PM
job hunt Robert0380 General 3 09-17-2003 07:01 AM
Browser Hijacking frkstein Linux - General 1 04-18-2003 06:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration