PDA

View Full Version : check this non-sense out


theboss
09-18-2007, 06:19 AM
I don't think this is ohh soo easily possible. To get someone screen feed you need access to their remote desktop or install some kind of back door both of which are 100% out of wireless security scope. And lets not forget the claimed "readily available software". I haven't heard one which will crack WEP and show me someone screen feed. Geez..bad example of how media will spoon feed propaganda to make some quick buck and stir controversy. Someone keep a check on them for god sake.

video link:

youtube.com/watch?v=pgBHjZUKW54

elazar
09-18-2007, 07:26 AM
Aside from a BoF attack which could run some shellcode and then install VNC like software, this is would be technically impossible. Assuming at least one is running XP SP2 with the firewall enabled, you will not be able to use open shares or connect to RPC to execute files. Remember, HKLM\SYSTEM\CurrentControlSet\Control\Lsa is you best friend and worst enemy...

wvdmc
09-19-2007, 01:03 AM
What about using the remote browser plugin for Ettercap? All the information they gathered was his web activity and e-mail. All they needed to do was get into the network and run Ettercap.

elazar
09-19-2007, 01:18 AM
From the look of the video, it looks like they were doing a screen scrape, which is impossible with ettercap.

EnculeurDePoules
09-19-2007, 06:46 AM
I don't think this is ohh soo easily possible. To get someone screen feed you need access to their remote desktop or install some kind of back door both of which are 100% out of wireless security scope. And lets not forget the claimed "readily available software". I haven't heard one which will crack WEP and show me someone screen feed. Geez..bad example of how media will spoon feed propaganda to make some quick buck and stir controversy. Someone keep a check on them for god sake.

video link:

youtube.com/watch?v=pgBHjZUKW54

ha its very easy, if you exploit the official security flaws!
im not sure if im allowed to post that but we installed a "fake os" with WMware? (virtualisation) and a XP unpatched, and we tried the flaw with a software called metaxploit!
its amazing what you can do! My friend even created an account with admin privileges on my computer, "under my nose"!!
We could also download and execute a .exe without the firewall or antivirus to notice!
I mean the point is, you need to always keep up to date with security! thats the "scope" you are talking about?

streaker69
09-19-2007, 06:50 AM
ha its very easy, if you exploit the official security flaws!
im not sure if im allowed to post that but we installed a "fake os" with WMware? (virtualisation) and a XP unpatched, and we tried the flaw with a software called metaxploit!
its amazing what you can do! My friend even created an account with admin privileges on my computer, "under my nose"!!
We could also download and execute a .exe without the firewall or antivirus to notice!
I mean the point is, you need to always keep up to date with security! thats the "scope" you are talking about?

Unless you installed a thirdparty firewall on the machine, then the XP wouldn't have a firewall installed unless you upped it to Sp2.

elazar
09-19-2007, 08:07 AM
ha its very easy, if you exploit the official security flaws!
im not sure if im allowed to post that but we installed a "fake os" with WMware? (virtualisation) and a XP unpatched, and we tried the flaw with a software called metaxploit!
its amazing what you can do! My friend even created an account with admin privileges on my computer, "under my nose"!!
We could also download and execute a .exe without the firewall or antivirus to notice!
I mean the point is, you need to always keep up to date with security! thats the "scope" you are talking about?

Sadly, there are a lot of those out there...

beakmyn
09-19-2007, 11:22 PM
eeye.com/html/products/iris/ will sniff the network and re-assemable the packets in near real-time.

I heard about this product years ago and it looks like now they've got a free trial.


Complete Packet Reconstruction

Reconstruct files and web-browsing sessions back into their original format on the local network, capturing a clear and concise image of the integrity of the network and associated traffic.


You'll see their "web window" is running inside another program but not a VNC session.

theboss
09-22-2007, 04:35 AM
ha its very easy, if you exploit the official security flaws!
im not sure if im allowed to post that but we installed a "fake os" with WMware? (virtualisation) and a XP unpatched, and we tried the flaw with a software called metaxploit!
its amazing what you can do! My friend even created an account with admin privileges on my computer, "under my nose"!!
We could also download and execute a .exe without the firewall or antivirus to notice!
I mean the point is, you need to always keep up to date with security! thats the "scope" you are talking about?

We all are well aware of it and experienced it at some point in life. Thats how all the nasty adware & malware gets installed on your computer after visiting unsafe site. However, all of that falls in a universe other than wireless security. You can show off hacked screen feeds to highlight vulnerability of some OS however network medium has least to do with it.

EnculeurDePoules
09-22-2007, 04:39 AM
We all are well aware of it and experienced it at some point in life. Thats how all the nasty adware & malware gets installed on your computer after visiting unsafe site. However, all of that falls in a universe other than wireless security. You can show off hacked screen feeds to highlight vulnerability of some OS however network medium has least to do with it.

haa I realize now that I have seen some urls looking exactly like in metaxploit, for the "url exploits"!!

aha bastards!
I actually never thought it was used except for simple hackers!