Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics


Specialist Topics Suggestions for topic sections welcome!

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-23-2009, 12:59 PM
Junior Member
 
Join Date: Sep 2009
Posts: 6
Default Blind TCP Hijacking

Hi all, I was reading this:
www . phrack . com / issues.html?issue=64&id=13&mode=txt
and it's a good way to learn in depth how TCP works, and although making a basic tool to discover sequences and port wouldn't be such a pain, there some problem shown in this article that may be solved by using more evolued algorithms, like being aware of user trafic by making stats to discover IP_ID ...
I wonder if some of you knows some tools to hijack tcp sessions.
Reply With Quote
  #2 (permalink)  
Old 09-24-2009, 09:19 AM
Member
 
Join Date: May 2008
Posts: 35
Default

Quote:
Originally Posted by nekkro-kvlt View Post
Hi all, I was reading this:
www . phrack . com / issues.html?issue=64&id=13&mode=txt
and it's a good way to learn in depth how TCP works, and although making a basic tool to discover sequences and port wouldn't be such a pain, there some problem shown in this article that may be solved by using more evolued algorithms, like being aware of user trafic by making stats to discover IP_ID ...
I wonder if some of you knows some tools to hijack tcp sessions.
well i wrote a small program which calculates the correct sequence number and build packets from the scratch and responds to request it is still in the priliminary stages and work on broadcast networks (wifi targeted) it can be downloaded from here rcx.sourceforge.net

i know the program is pretty shitty at this moments and if anybody wants to help me improve it can join the project.
Reply With Quote
  #3 (permalink)  
Old 09-24-2009, 11:18 AM
Gitsnik's Avatar
Senior Member
 
Join Date: Jun 2009
Location: The Crystal Wind
Posts: 637
Default

Quote:
Originally Posted by Cryptid View Post
well i wrote a small program which calculates the correct sequence number and build packets from the scratch and responds to request
Kevin famously did something exactly like this to mess with the dumbass who "caught" him - and TCP was modified to deal with the attack.

Nowadays, predicting TCP sequence numbers blind is problematic at best, albeit it is possible to fake the entire handshake completely blind, and if you are in a position to do so, it is far easier to MiTM the connection, or introduce tcp-breaks (look into injecting commands into telnet streams).

Datenterrorist has a good write up, TCP Hijacking tools in Perl or something like that, which is quite useful.
__________________
Never underestimate the power of human stupidity - it is like a force of nature, capable of destroying even the most well laid plans.
Reply With Quote
  #4 (permalink)  
Old 10-04-2009, 12:03 PM
fnord0's Avatar
Member
 
Join Date: Jul 2008
Posts: 97
Default

Quote:
Originally Posted by Gitsnik View Post
Datenterrorist has a good write up, TCP Hijacking tools in Perl or something like that, which is quite useful.
good call Gitsnik, I never seen that blog b4 (re: datenterrorist), they've got some good information there for sure... here is what I found, the link for the page you are talking about = Programming TCP Hijacking Tools in Perl « Datenterrorist

also the P.A.T.H. project is referenced (probably a good place for more info on the subject) = P.A.T.H. -- Perl Advanced TCP Hijacking
Quote:
P.A.T.H is a collection of tools for inspecting and hijacking network connections.collection

Programming languages: Perl and C
Latest release: 0.8
Current version: P.A.T.H. preSTABLE
Supported operating systems: GNU Linux, FreeBSD

The project consists of a packetgenerator (constructing TCP/IP, UDP/IP, ICMP and ARP packets), a RST daemon (to reset TCP connections), a sniffer (with special mail and telnet modes), an ICMP redirection tool (to implement man-in-the-middle attacks with icmp redirect messages), an ARP redirection tool, an IDS testing tool and an automatic hijacking daemon for plain protocols (like telnet).

All tools feature both a Tk GUI and a terminal interface.

Please note that this project is in BETA state!!!
...and it comes with absolutly no warranty...

Don't forget to read the FAQ!
best of luck... this is a topic that is quite interesting, especially since there is some good perl info out there ( I like perl alot )
__________________
see the fnords
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:54 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2