Jump to content

Packet Crafting help


Recommended Posts

I have been tasked with helping develop a packet crafter for a project. Long story short, I have create a packet crafter, explain how it works, and present it to a few professors. From my understanding packet crafting is like MAC spoofing and IP spoofing combined. The basic idea is to take in packets, modify them, send them back out. But appearing that the packets are coming from a different location. I've just started my research but if anyone has any useful links and tips, I'd appreciate your help.

My first question is how would I start creating one?

2) What would be the best language to use?

3) Any suggestions for software?


(If my understanding of the topic is incorrect or off somewhat please correct me but like I mentioned I'm in the early stages of research.) :blink: As I progress with this project I will upload my results.

Link to comment
Share on other sites

Python & Scapy - is good for creating/manipulating packets

Ettercap can manipulate packets based on a series of filters.

Not sure if Netdude can do what you want, but you could capture with wireshark, modify with netdude, and resend with tcp-relay

Link to comment
Share on other sites

  • 2 months later...

Look at any given piece of software intended to perform a Man In The Middle attack. It eavedrops data from someone and then sends it on, as-is, to its intended recipient. From that point on all you have to do is make it do something a bit more interesting than just 'send on'. Hand-crafting packets means you need to know about an Ethernet, IP, TCP, UDP and, yes, C as in the language. There may be some higher-level language that can also mangle a packet, but what you're doing is just shy of chiseling electrons out of a network cable. It doesn't get much lower level than this. And if you want low level, you're talking C or ASM, pure and simple.

Look at Wireshark. Let it trace some bit of communication you generate. See what it records. Understand what the various bit fields mean. Know what you can change and what would require some work to change (like the need to take checksums into account). Do you know what you _want_ to change? Just the originating address? If so, where in the packet is it? How do you ensure you get it and not the intended recipient?

Think the process through. Draw a diagram with the current flow of information. Decide how you intend to influence this. From this you can determine what information flows you must intercept and what you'll do with them (and, most importantly, WHY you want to do just that in just that way) at which point you can start working out just how you can manouver your hardware in such a way that you do in fact intercept those flows.

How much of this did you work out already?

Edited by Cooper
Link to comment
Share on other sites

We've haven't meet up as a group anymore, the club isn't meeting anymore due to lack of organization. Currently I am entering exam week and am going to focus on those but this will be my project for this summer. Thanks for all the help guys! Sorry for such a late reply!

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...