Hak5 Forums: Jasager Plugins? Tools for pwning? - Hak5 Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Jasager Plugins? Tools for pwning? Rate Topic: -----

#1 User is offline   El Di Pablo 

  • Hak.5 Fan +
  • PipPipPip
  • Group: Members
  • Posts: 55
  • Joined: 02-October 08
  • Gender:Male
  • Location:San Diego, CA
  • Interests:I am an Uber tech geek. I generally spend most of my time either playing with something techie, or writing about something techie. Other than that, I suppose my family takes up the rest of my time.

  Posted 02 October 2008 - 01:19 PM

Hey guys, I ran into Darren at Toorcon and mentioned to him that I was going to do my final paper on the Jasager project in my Network Security class.

My professor likes the idea, but wants me to add more stuff to the report (e.g. other tools) I can use once the victims connect to my pineapple.

I thought about adding a section on Metasploit/db_autopwn, but since we already touched on that in class I don't want to use that.

Any ideas would be helpful.

Thanks,
-EDP
_________________________________________________
If I'm not on the Hak5 Forum, you can find me
getting my geek on at www.Bauer-Power.net
0

#2 User is offline   digininja 

  • Elite
  • PipPipPipPipPipPipPipPipPipPipPipPip
  • Group: Global Moderators
  • Posts: 2,082
  • Joined: 19-December 06
  • Gender:Male
  • Location:Sheffield, UK

Posted 02 October 2008 - 03:22 PM

If you want to contribute, look at the todo list. If you have any specific areas you are interested in mail me (details on site) and I'm happy to discuss them. As I've said a few times, I have loads of ideas for extensions and upgrades but not got much time to fit them in.
0

#3 User is offline   El Di Pablo 

  • Hak.5 Fan +
  • PipPipPip
  • Group: Members
  • Posts: 55
  • Joined: 02-October 08
  • Gender:Male
  • Location:San Diego, CA
  • Interests:I am an Uber tech geek. I generally spend most of my time either playing with something techie, or writing about something techie. Other than that, I suppose my family takes up the rest of my time.

Posted 02 October 2008 - 05:19 PM

QUOTE (digininja @ Thu, 02 Oct 2008 13:22:33 +0000) <{POST_SNAPBACK}>
If you want to contribute, look at the todo list. If you have any specific areas you are interested in mail me (details on site) and I'm happy to discuss them. As I've said a few times, I have loads of ideas for extensions and upgrades but not got much time to fit them in.


Hi digininja, it doesn't necessarily have to be a plugin for Jasager/ It could just be a tool running on your laptop. I'll take a look at your todo list though. Thanks!
_________________________________________________
If I'm not on the Hak5 Forum, you can find me
getting my geek on at www.Bauer-Power.net
0

#4 User is offline   digininja 

  • Elite
  • PipPipPipPipPipPipPipPipPipPipPipPip
  • Group: Global Moderators
  • Posts: 2,082
  • Joined: 19-December 06
  • Gender:Male
  • Location:Sheffield, UK

Posted 02 October 2008 - 05:32 PM

Well I maintain karma which is the laptop base for Jasager, if you need any help with that let me know too.
0

#5 User is offline   El Di Pablo 

  • Hak.5 Fan +
  • PipPipPip
  • Group: Members
  • Posts: 55
  • Joined: 02-October 08
  • Gender:Male
  • Location:San Diego, CA
  • Interests:I am an Uber tech geek. I generally spend most of my time either playing with something techie, or writing about something techie. Other than that, I suppose my family takes up the rest of my time.

Posted 07 October 2008 - 12:03 AM

Update: I decided to write my paper on using Jasager in conjunction with Sidejacking using Ferret and Hamster. I will let you all know how I do grade wise.

If you are not familiar with Sidejacking, here is a cool Youtube video I found: http://www.youtube.com/watch?v=nFNFa-48lpI
_________________________________________________
If I'm not on the Hak5 Forum, you can find me
getting my geek on at www.Bauer-Power.net
0

#6 User is offline   RchGrav 

  • Newbie
  • Group: Active Members
  • Posts: 6
  • Joined: 07-October 08

  Posted 07 October 2008 - 11:16 PM

QUOTE (El Di Pablo @ Tue, 07 Oct 2008 01:03:45 +0000) <{POST_SNAPBACK}>
Update: I decided to write my paper on using Jasager in conjunction with Sidejacking using Ferret and Hamster. I will let you all know how I do grade wise.

If you are not familiar with Sidejacking, here is a cool Youtube video I found: http://www.youtube.com/watch?v=nFNFa-48lpI



Thats Pretty Sick. Looks like a pretty neat trick. Now you just need to figure a way to provide actual internet access with one and be able to be on the same network with your laptop. Too bad you can't just TAP another WIFI signal and provide AP services over Karma at the same time. Maybe use your lappie to reshare another WIFI signal with ICS? Hmm...
0

#7 User is offline   El Di Pablo 

  • Hak.5 Fan +
  • PipPipPip
  • Group: Members
  • Posts: 55
  • Joined: 02-October 08
  • Gender:Male
  • Location:San Diego, CA
  • Interests:I am an Uber tech geek. I generally spend most of my time either playing with something techie, or writing about something techie. Other than that, I suppose my family takes up the rest of my time.

Posted 08 October 2008 - 01:04 AM

QUOTE (RchGrav @ Tue, 07 Oct 2008 21:16:40 +0000) <{POST_SNAPBACK}>
Thats Pretty Sick. Looks like a pretty neat trick. Now you just need to figure a way to provide actual internet access with one and be able to be on the same network with your laptop. Too bad you can't just TAP another WIFI signal and provide AP services over Karma at the same time. Maybe use your lappie to reshare another WIFI signal with ICS? Hmm...


Yeah, that is basically the scenario I proposed in my paper. I would have a laptop with a Mobile wireless card, and I would bridge the internet connection between that and my connection with the Fon.

Now with all the packets flowing through me, I can capture browser session traffic with Ferret from all of the unsuspecting hot spot suckas...errr... users then funnel those packets through Hamster and start "Sidejacking" their browsing sessions. Pure pwnage!

I give my presentation tomorrow. I'll let you all know how I do.
_________________________________________________
If I'm not on the Hak5 Forum, you can find me
getting my geek on at www.Bauer-Power.net
0

#8 User is offline   El Di Pablo 

  • Hak.5 Fan +
  • PipPipPip
  • Group: Members
  • Posts: 55
  • Joined: 02-October 08
  • Gender:Male
  • Location:San Diego, CA
  • Interests:I am an Uber tech geek. I generally spend most of my time either playing with something techie, or writing about something techie. Other than that, I suppose my family takes up the rest of my time.

Posted 09 October 2008 - 12:08 AM

Alright, report/presentation is complete. Got an A by the way. Teacher liked the idea of using Jasager over the classic MiTM because you could potentially pwn multiple users at once rather than the classic arp poisoning/MiTM with Cain or similar program where you can really only target one at a time.

There will be some new visitors to the forum looking to hack their Fons now as everyone in the class wants to try this.

Thanks for everyone's help!
_________________________________________________
If I'm not on the Hak5 Forum, you can find me
getting my geek on at www.Bauer-Power.net
0

#9 User is offline   Darren Kitchen 

  • Hak.5 Junkie
  • PipPipPipPipPipPipPipPipPipPipPipPip
  • Group: Root Admin
  • Posts: 3,364
  • Joined: 26-July 05
  • Gender:Male
  • Location:Williamsburg, VA
  • Interests:Podcasting, Hacking, Beer, Ballroom Dancing, Photography, Gaming, IT, Sushi, Beer, Aviation, Phreaking, Stop Motion

Posted 21 November 2008 - 01:22 PM

Bauer,

Awesome stuff dude and congrats on the A. Wish I had seen this thread before doing the sidejacking pineapple segment on 412 else I'd have given a shoutout. I'll have to bring it up on the next ep.
Posted ImagePosted ImagePosted ImagePosted Image
0

#10 User is offline   OiNK 

  • Hak.5 Fan
  • PipPip
  • Group: Members
  • Posts: 19
  • Joined: 05-October 08

Posted 30 November 2008 - 01:48 AM

Epic.

This really quick frankly terrifying... although i must try this out next time im bored @ wifi spot hehe thanks for bringing this to my attention biggrin.gif!

....and so it begins....all your base are beloing to us lol
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users