Remote Exploit Forums

Go Back   Remote Exploit Forums > Archives > BackTrack v2.0 Final


BackTrack v2.0 Final Released 6th of March 2007 Please do not make posts related to BackTrack 2 Beta here!

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-29-2008, 03:47 PM
Member
 
Join Date: Mar 2008
Location: CA
Posts: 89
Send a message via MSN to >Dart>
Default DoS Attack?

This week we have been talking about linux in my networking class. The class is made up of 12 computers with 2 people per a group. 4 of the computers run Windows XP SP1, 4 more run Windows Server 2003 and the rest run Linux. But this Week is "Linux" week and the professor passed out BackTrack2 CDs to everyone. He said BT3 is not comtabable with the towers due to video problems but BT2 works fine.

We hookup 2 hubs to a central Linksys router (defult settings) using DHCP (Dhcpcd). So far all we've done is answer questions about Wireshark, played with SSH, FTP and TFTP and mess with VI and web servers (Under services)

Today we are going to talk about DoS attacks. Im not really sure what the teacher has in mind....but I was wondering: Does BT2 have anything on it that can can flood the network, I know you could use Ethercap to do "Man in the Middle" attack and revert traffic to some null MAC/IP which would freeze the network. Or is there any other way to cause a DoS using a BT2 CD? I bet there is but I have had no luck in finding it. Thats why im posting.
Reply With Quote
  #2 (permalink)  
Old 10-29-2008, 03:52 PM
ShadowKill's Avatar
Senior Member
 
Join Date: Dec 2007
Location: /dev/null
Posts: 918
Default

Quote:
Originally Posted by >Dart> View Post
This week we have been talking about linux in my networking class. The class is made up of 12 computers with 2 people per a group. 4 of the computers run Windows XP SP1, 4 more run Windows Server 2003 and the rest run Linux. But this Week is "Linux" week and the professor passed out BackTrack2 CDs to everyone. He said BT3 is not comtabable with the towers due to video problems but BT2 works fine.

We hookup 2 hubs to a central Linksys router (defult settings) using DHCP (Dhcpcd). So far all we've done is answer questions about Wireshark, played with SSH, FTP and TFTP and mess with VI and web servers (Under services)

Today we are going to talk about DoS attacks. Im not really sure what the teacher has in mind....but I was wondering: Does BT2 have anything on it that can can flood the network, I know you could use Ethercap to do "Man in the Middle" attack and revert traffic to some null MAC/IP which would freeze the network. Or is there any other way to cause a DoS using a BT2 CD? I bet there is but I have had no luck in finding it. Thats why im posting.
Look at an app called Charon. Our own ShamanVirtuel wrote it. Enjoy....
__________________



"The goal of every man should be to continue living even after he can no longer draw breath."

~ShadowKill
Reply With Quote
  #3 (permalink)  
Old 10-29-2008, 05:01 PM
Member
 
Join Date: Mar 2008
Location: CA
Posts: 89
Send a message via MSN to >Dart>
Default

I dont think Charon is on BT2? I did find Dhcpx Flooder, do I plug in the IP address of the router? Will it flood the network?
Reply With Quote
  #4 (permalink)  
Old 10-29-2008, 05:12 PM
ShadowKill's Avatar
Senior Member
 
Join Date: Dec 2007
Location: /dev/null
Posts: 918
Default

Quote:
Originally Posted by >Dart> View Post
I dont think Charon is on BT2? I did find Dhcpx Flooder, do I plug in the IP address of the router? Will it flood the network?
No, it's not packaged with BT2, but you can just install it yourself....
__________________



"The goal of every man should be to continue living even after he can no longer draw breath."

~ShadowKill
Reply With Quote
  #5 (permalink)  
Old 10-29-2008, 08:48 PM
Member
 
Join Date: Mar 2008
Location: CA
Posts: 89
Send a message via MSN to >Dart>
Default

Ok, I guess ill have to try that out later.

Well class is over, I opened Wireshark and fired up dhcpx and BOOM It looked liek the router was trying to renew its lease (192.168.1.1)??? Not sure what that would do but it did "Nothing" to anyone. We could still move files back and forth. But I wonder if someone disconnected, and the DHCP server was being flooded, could someone reconnect?

Would there be a way to kick some people off the network and start the flooding and ask them to reconnect?

My teacher says "Asking" them to get off the network would "not" be a real world situation. He was a linux admin for 30 years....He loves "Real World Situations"

I know how to kick someone off the network if they are wireless...but not wired?

And could someone post the download link for Charon...all I could find is this: http://www.softpedia.com/get/Interne...s/Charon.shtml and I dont think that is it cause it runs on Window$.

Last edited by >Dart>; 10-29-2008 at 08:50 PM.
Reply With Quote
  #6 (permalink)  
Old 10-29-2008, 08:50 PM
streaker69's Avatar
Senior Member
 
Join Date: May 2007
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 3,665
Default

Quote:
Originally Posted by >Dart> View Post
Ok, I guess ill have to try that out later.

Well class is over, I opened Wireshark and fired up dhcpx and BOOM It looked liek the router was trying to renew its lease (192.168.1.1)??? Not sure what that would do but it did "Nothing" to anyone. We could still move files back and forth. But I wonder if someone disconnected, and the DHCP server was being flooded, could someone reconnect?

Would there be a way to kick some people off the network and start the flooding and ask them to reconnect?

My teacher says "Asking" them to get off the network would "not" be a real world situation. He was a linux admin for 30 years....He loves "Real World Situations"

I know how to kick someone off the network if they are wireless...but not wired?
"You're not thinking 4th dimensionally, Marty!"

What the quickest and easiest way to kick alot of people off of a network without interacting directly with them?

Pull the power on the switch.
__________________
A 3rd Party Security Audit is the IT equivalent of a Colonoscopy, it's long, intrusive, and when it's done you'll have seen a lot of things you really didn't want to see, and you'd definitely remember that you had it done.

I baby harp seals.
Reply With Quote
  #7 (permalink)  
Old 10-29-2008, 09:51 PM
Member
 
Join Date: Mar 2008
Location: CA
Posts: 89
Send a message via MSN to >Dart>
Default

Ya that would work...but Im trying to avoid kicking off myself....I could "accidentally" unplug a few off of a hub...but there's no way to do it remotely...easily? But pulling plugs would work I guess...
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:51 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2