About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-10-22, 17:52
75mab99 75mab99 is offline
Regular
 
Default Question on hacking

I am curious about something regarding "internet security". Here's an example -- I read all the time about instant messaging being "unsecure". I understand very clearly how easy it is to intercept traffic on a local network. What I am curious about and if anyone could explain in genreal terms the process of HOW -- say my neighbor down the street would go about intercepting my e-mail my MSN MEssenger message, and the like.

I mean getting IP address is easy, but how hard is it for the average Johnny-intermediate-computer-user to do this?

I am not looking for a how to manual, or programs or anything, just wondering what process is and what the odds are of my communications being picked up. For the sake of explanation specifics I am on a cable modem.

Hope my question makes sense and someone will be willing to answer. Thanks!

 #2 
Old 2002-10-22, 23:34
maxim420 maxim420 is offline
Regular
 
Default Re: Question on hacking

I cant tell you exactly how the message is intecepted, but I can tell you that all defenses are lowered by your computer when the "handshake" is made to another computer. In a one on one chat session, you are telling your computer that the person you are connected to is completely trustworthy and you do not need any sort of firewall or wanything. So I believe it would be alot easier to intercept your traffic when you are in this mode. I hope this helped a little.
 #3 
Old 2002-10-23, 20:14
Regular
 
somewhere up there
Default Re: Question on hacking

I don't think they can intercept you stuff unless they tap your line. I think the real problem of interception is with wire-less networks. So I don't think you should worry.
 #4 
Old 2002-10-23, 21:42
cense cense is offline
Regular
 
Default Re: Question on hacking

the prefered, and one of the only methods of tapping such connections is the "man-in-the-middle" type attack. As stated before, this attack is usual started when you are setting up a connection with a peer.

For the attacker to view what both/all sides are "saying" they would have to covertly "tell" all computers engaging in this communication to forward requests to them first, then the attackers system would forward the data onto the "real" destination.

This attack is fairly seemless to the users who are chatting unless they are carefully watching WHERE their chat messages are destined.

Other attacks are possible, such as breaking into email servers and just plain reading email but for IM, man-in-the-middle is the simplest way I can think of, which in itself means very little since I am not some uber-elite-crazy-hacker-guy.
 #5 
Old 2002-10-24, 10:30
skalez skalez is offline
Regular
 
Default Re: Question on hacking

But the question is, does anyone here even know how to pull off man-in-the-middle? I know it's done by something called ARP cache poisoning somehow (and otehr methods) but that's just name-dropping, my searches have taken too long for too little results and I have gotten bored on the subject.
 #6 
Old 2002-10-24, 10:35
skalez skalez is offline
Regular
 
Default Re: Question on hacking

Arr, I'm dumb. What I meant was firing off packets on the "victim's" local network to your sniffer.
 #7 
Old 2002-10-24, 13:33
cense cense is offline
Regular
 
Default Re: Question on hacking

On a local network, switched environment, you are partially correct, ARP cache poisoning works well. This is more of a global (to local network/subnet) attack than a directed attack. A successful ARP cache poisoning and you will see all of the traffic going OUT of the local network for as long as you can keep confusing local clients and the switch.

The theory of this attack is based on how switches make decisions and how the TCP/IP stack and Ethernet specifications handle each other. Switches are layer 2 (like NICs) and thus only look at MAC addresses, NOT IP addresses. ARP is Address Resolution Protocol. ARP translates IP addresses into MAC addresses. Ok. The attack works by you flooding the local network or subnet with ARP data saying that YOUR MAC address is associated with the default gateway's (router) IP address (ARP Reply packets).

What this achieves is rather simple, but here is a possibly confusing description of how it works (3 hours of sleep):

Client machines on the subnet are configured with the gateway's IP. When they send data out of the subnet, the gateway's IP is translated to a MAC (through ARP) so that your machine can append the appropriate MAC address to its Ethernet header. The switch watches all data transmission so it knows what MAC address is on what physical port. The flooding has confused the switch and all clients on the switch/subnet into thinking that your MAC is associated with the default gateway's IP, thus all clients wanting to send data to the default gateway will be appending YOUR MAC address to their Ethernet headers and thus telling the switch to forward any external request to you instead of the default gateway. This forwards all data destined for the default gateway, through your machine.

Obviously, you have to re-direct that data back to the gateway somehow for the clients to get successful connections outside of the subnet when you are preforming this attack.

Does that explain ARP cache poisoning with any clarity?
 #8 
Old 2002-10-26, 07:01
skalez skalez is offline
Regular
 
Default Re: Question on hacking

Yeah, sorry, I didn't make myself clear, and made write that big post :S. You probably helped someone though. What I meant was how do you do it over the net?
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics