View by:

Introducing Interceptor: The network tap and rogue wireless access point

Wednesday, March 18th, 2009 – running time 23:01
The perfect primate for pen testers is none other than network monkey. Introducing Robin Wood's Interceptor -- on this episode we hack the Fon+ and turn it into a network tap and rogue wireless access point. Sniff the LAN from across the street or hack the network from the inside out! Learn how Network Monkey Pirates your Packets today!

Our friend digininja is at it again. On this episode we feature Robin Wood's latest hack based on none other than the Fon+ wireless router.

Interceptor is a wireless wired network tap. Simply put you place it in line on an ethernet cable, then connect to it via a special wireless access point. Once connected and running the Interceptor scripts you'll be able to sniff all of the traffic passing across the wire.

Interceptor doesn't affect TTL and adds minimal latency to packets. It doesn't associate to the target network so discovering an active Interceptor on your LAN isn't trivial.

This tool is perfect for pen testers. The device inexpensive, based on the Fon+ router and using open source software. It is small enough to fit behind a network wall plate, inside a plush monkey, or even inside a network switch or other gear.

In this episode we demonstrate the usage, illustrate the installation and speak with the developer Robin Wood.

You can download the software and play with it yourself from digininja.org/interceptor and find support and discussion at the Hak5 Interceptor Forum.

Thanks for watching, subscribing, and most of all supporting the show. On a related note custom commissioned WiFi Pineapples running Jasager are now available.

We return next week with a regular format show. Don't forget to submit your questions@hak5.org and feedback@hak5.org and trust your technolust!

Highlights
Hak5 ( 2:43, 3:20, 6:50, 13:52, 14:10, 2:43, 3:20, 6:50, 13:52, 14:10 ) serial port ( 6:18, 6:18 ) Blu-ray ( 22:14, 22:14 ) Kennedy space ( 14:48, 14:48 ) Hak5 ( 2:43, 3:20, 6:50, 13:52, 14:10, 2:43, 3:20, 6:50, 13:52, 14:10 ) serial port ( 6:18, 6:18 ) Blu-ray ( 22:14, 22:14 ) Kennedy space ( 14:48, 14:48 )

Automatically Generated Transcript(may not be 100% accurate) ( more )

" War."

" a pack five is brought to you by godaddy. Netflix. In Squarespace."

" Money and take him out. Mr. Wright once again my name is back. Right. Well. Let's forget. To whom it may concern. -- The fabulous mr. Wright. Recently purchased. A bottle of the troops. About an hour after the taking the supplement. I happen to develop a rather humongous. Scratch that. A rather large."

" Enter."

" Yes I took the ointment. No it's not working. Its its its. Hey got flower delivery for Becky Stewart. Excellent. I -- admire."

" Exciting. This little guy."

" Albright and was forgot this is the admirer monkey goes with the flowers. It what's what he had."

" It plugs into your computers Internet and when you go to your profile page every secret admirer unlike FaceBook he lights up and play the song for you."

" I've honestly. Not work. Yakking cell. We're can be -- nobody uses veto. -- Eight oh. Oh yeah."

" Okay less often I will stop yelling at you when you actually prescribe me something to work. Not it's my fault. That's -- she finds it. -- If you seen my bowl cream you know the one for my extra large. --"

" This month's Lan party is insurgency monitoring infantry combat we're playing over and -- agency dot Hak5 dot org. On March 28 at 3 PM eastern. If you're not till indisputable insurgency thank you can -- of -- that Squarespace dot com and vote for your favorite -- game. And I have to thank our wonderful sponsors Squarespace. Squarespace is a publishing system for anyone looking about a blog portfolio or any kind of website they powering large businesses to blogs. And Squarespace gives the opportunity to. Build pages that are just as powerful and flexible as those of the big dogs. And you can go to Squarespace dot com right now for a two week free trial membership. And you can see use code Hak5 that's H a K five for 10% off the life of your service."

" Interceptors the network tapped the -- a wired connection over Rogue wireless access point. Well in May have become significantly paranoid about pineapples and no wireless traffic too often we take for grant the security of a wired networks. Whether -- home work or abroad the prospect -- in in the middle attack poses a significant threat especially deal with an encrypted communications. Hackers and pen testers -- years have exploited the nature of the network by becoming the man in the middle using techniques such as our cache poisoning. And network administrators have you sniffing tools like wire shark in conjunction with -- network -- to troubleshoot congestion. But these tools and techniques require a level of access and presence that isn't always viable. So what if there were a device that could see it in line on a wired network passively monitoring the packets. And what of this device came with the road wireless access point that an attacker could access to initiate a private tunnel and tap into that traffic. This device would be small with the ability to sit behind the network won't play. Or inciting Q plus she with the ability to social engineer secretaries. Or maybe it could attach to the back of the PC with a phony telephone company logo. And all the wild the attacker could connect wirelessly from the convenience of a black van parked outside the corporate office and here past the file without notice. Unobstructed to latency time to live with the same wireless security bill to keep the black -- out. This little device could stand stealth -- from nine to five then at the drop of the hat from passive to active stroll in the network from the inside out. The devices speak of is none other than Robin woods interceptor and today we'll be building one bad little monkey in the middle. So let's get started. First we'll need a wireless -- with two or more ethernet ports capable of running our favorite embedded at less -- to be RT. For this will be using it goes so hackable on plots. These little guys were designed and manufactured by act on and -- flash from custom font firmware. The basic idea is that they let you share your Internet telephone heiress an intern and borrow a cup of packets from other scenarios while ago. It's a noble idea and great community and we're happy to see these little creatures in the wild. But as always we've got plans for this little routers. He's in the power of fair use in the ancient art of ninja hacking skills will unlock this little from Tara. Instill interceptor stuffed inside a plus monkey and weaponized a little guy. But first a quick look under the hood. One plus runs on a lock down version of OW RT. Requires seven full to power and runs on a 183. Megahertz -- processor. At sixteen megs of ram it makes a flash tool 10100 megabit ethernet ports and speaks attitude at eleven B and G. He also sports a serial port which is great from breaking an omni directional one point five dvi antenna. And the standard RPS and they connector for more powerful intact. Now let's get hacking first -- computer emergency -- some ethernet cables and some special software. We'll be doing this in Linux however you can do the same in windows or Mac as long as if pearl SCH -- CP opened VP NT FT PD. And TCP jumper wires -- All of the packages the software used in this are available did you -- dot org or Hak5 Wiki. Before we begin we'll need a copy of open to the RT eight points here than nine for a Ferris. VMware and -- in May and root out squash a fast NT FT PD typically found -- slash T ftp built. Now will begin by bringing up the ethernet interface on a PC as 190 -- one got 254. Connecting Internet cable between the PC and fun plus easily import and run -- it to PL 1921681. Someone might want twit connected to read do via Tel net war one to flash the firmware. So issue -- and it. Then load the kernel from T ftp. With load attack our tech B. Percent free Menlo. Open to the RT there us -- those in May and bright the image with this create tech T. Zero X 800. 41000. -- 841000. Via live next stop being dot -- this takes a while so want to take a break and have a -- they're good for you. Next load the file system from T ftp -- load -- car tax -- percent premium low. Open to the RT -- terrorist tack room dot squash FS and bright -- image with this create tech -- Zero X six F 0000. -- fast. This part takes a long while considering banana smoothie in a blender mix bananas ice milk and your favorite yogurt and all right once a file system is written will need to configure -- issue -- configure an answer true to the first question. Then answer the following the script. Has slowed -- LVM. The next obvious and I L seven exact. One a 22 Pritzker time -- no boot peak network configuration. No Gateway IP address of local IP of 192 don't want to take that one one. A network mask of 255255. 255 zero. The default server IP set to 190 you don't want succeed at one point 254. A consul baud rate of 9600. And the GDP report at 9000. Tell red dude not to force consul for special to bug messages not to -- bug network news and finally go ahead and update the non volatile configuration. Issue reset and the connection we'll close that from."

" Our PC will go ahead -- 19 -- don't want to take 11. We should receive replies shortly. Tel net to when ninety don't want to -- that one one and will be greeted by open WRT kamikaze show. Is she passed WTO -- monkey business twice. Now exit from power PC will go ahead and necessary to revert to brute 190 don't want succeed one one. After accepting certificate. Once again be greeted by opened of the Ortiz show. Now we'll open another terminal on -- PC and navigate to the directory containing interceptors required packages. Will be as seeking these files over to the fun plus in slash TMP. But he could also -- these packages from a local HTTP server using W gets. SEP start I PK 2190 Dublin succeed one -- one and slash TMP. Now back over on the fun plus we'll use OP KG to install all of the packages and slashed -- Finish off your banana smoothie or came -- on the -- bills Leo lid open SL AZ lid -- VPN live peaked cap and live Tina are installed and configured. You may also want to include the nano packages and any other goodies like nmap. Next we'll let that the wireless configuration. The important part here is to set disabled zero. Give the Wi-Fi interface in a society and seventies WPA. PS KTU. We'll also want to edit the network interface. Here we set the lynch static Britain's with a -- of 19 to -- once it's seen that one one and an interface name of -- zero point zero. The win will be called at zero point one. Now remove all entries from at C slash Arce got. HT TPD or -- mask. Back on our PC will want to grab the latest version of interceptor from did you do about work. Unpacked the tar and as he PD interceptor -- package to the fund plus in -- TNP. Switch back to the fun plus and instill interceptor with okay KG. Now we can start interceptor by issuing -- at C slash -- such interceptor. Start. From our piece he will need to create open VPN -- If you're not familiar with hoping geeky inning -- generation you can find more details on our forms. We start by copying the easy RSA files who are working directory an editing bars. Tweak the sample configuration and will be all set to build the keys. Issue bars clean install and build CA. Next issue build key server server. Then build key client one and build dot DH at this point you should have a bunch of -- certain key files. Only to a CP client one does hurt Clinton won the key and see aid concert 190 don't want to take a one to one. In slash interceptor slashed open VPN slash client. Now created your -- concerts where -- interceptor startup script is located and copied DH 1024 dot -- Server to assert server that key. And see a -- there. Finally were ready to test interceptor. Plugged the wind pored over from there into the switch and the limp or into a spare computer. Set it to run -- constant pinging or any other sort of traffic. This is the target that will be eavesdropping on shortly. Now back toward PC will need to connect the -- for wireless so let's created to -- PA supplicant config file with interceptor is there SS ID. And monkey business as -- password. Once that's complete issue to EPA's applicant attack DW EXT. Attack I 20 taxi. Like configuration files. Now that we're associated we need to manually set RIP address to ten 255. 255 to 253. -- attend -- 255 -- to touch 254. To ensure that interceptors running and then run the startup script. Open VPN connection should -- and you'll be asked for the root password when interceptor is ready to start team and longer. Now in new terminal run -- config and verified that -- zero is up. Tell TCP -- to listen to taps Euro or fire up -- you should now see all of the traffic between your target computer and the switch. That's it you ready to toss it in a monkey weaponized little primate and star pirating some packets -- on -- San wireless. When you're done with you passing attack go ahead and scan the network assign an IP address that's our hacking from the inside out. Or send your monkey of the Hak5 forms for more information about fund plus months. Interceptor extensions or other platforms interceptor supports."

" This week's trivia question it is what -- monkeys have the pleasure of being shot and the space atop an -- eighteen missile in 1959. Submit your answer to Hak5 dot org slash trivia and entered to win this week's given what -- and I have to thank our sponsor godaddy. Think smarter than the rest prove it and you could win big it's more space from godaddy.com has changed the way you use the Internet the way you blog the way you do business. The way you live your life. Create a blog or video story that shows how. You might just wind when he 5000. Dollars in cash prizes and free smart space for life. So head over to godaddy.com. Slash SS contest and now. Don't have -- smart space see what it's all about and save an additional 15% off your April 15 2009. Make sure use Kennedy space fifteen."

" To today we had pleasure having our friend Robin wood on brought in last time we saw is that an aircraft carrier we're talking my the other dog got. What's been up since. I think it we've and it's very com. The bush would look phones. Yeah that's your forte it seems. This particular -- there were talking about today interceptors based on me on plus. -- may -- you can explain to us some of the features of interceptors kind of how. It came to be."

" Rattled the insects. And that's what I could remember -- can buy it from let's talk column. When we -- but foam close to wired network counts of wireless exit will. Would be good idea -- network top and so since then -- playing with dates. I'll look below where it is say wireless why its network so. The idea race. Get a phone in talk in line and it its network. All the dates going across the two why knicks get spots on it through the wireless. And can then be sniffed all's well that -- so well that's not so much else."

" I think the idea of having that Rogue access point that's just sitting in line is actually beautiful maybe Khatami some of the software that that's involve the packages that actually. Make it all come together."

" Well initially the idea was just to use that IP tables aren't close all the -- there was going across the bridge on the phone. -- soil -- so they know he's in the media stunt that's. -- I don't look -- IP tables couldn't get it it working. So outside looking -- so its -- lot of people. I on the best thing we will wait world's package called the Malacca which she's from. Not seeing brochure thinks that this guy does set Stoltz. And what not to policy -- to expect XIDs sake Photoshop bullets. So sucks off. This floating all the stuff they call the rage -- soup Nazi era. -- it's an excellent stairways. Local but I couldn't get it working. Again and -- not asking it's on with some help from not say on the guy on the -- list. Heats. A box that resembles. We finally can the idea all of schooling to date so of -- yet. Eight -- and a YOX. Beat the X. I would put it all web sites now I've on the city cool it's Beck's way of giving it the -- I will wait and I lost a lot of they. So basically. Traffic across the wide in space he's flown on suit. Hey open began space. Sent through La -- wireless. And open he can suddenly threatened since the it's. Puts -- you didn't face that you can walk twit T Speedo all white shop."

" Now tell me a little bit about the hardware only of course your forte -- some fun we're doing the fun plus. It's -- harder because it'll run open WRT we get a nice that there's chips that. But is that is that all necessary is is this something that you can actually put together and another piece of hardware."

" I -- well a light Kelly yes again there are no cheese it's true and UH I was and the -- opt. So theoretically it should work on any. Device at least it's too quiet settings faces on the wireless. There will open the say. I'm gonna just try to at the moment but it's. It sold to stop the puck so don't see why it wouldn't work."

" So Robinson's we have 200 megabit ethernet and a 54 megabit wireless what's gonna happen there when there's a lot of traffic."

" So the reverend fully tested yet it's the sudden so it will be yet limitations the list. Of state or so -- make choppy coastal why it's a box and that it -- well what are the loyalists. You technical talk about the and open geek gadget she's gonna slow things down debates. I could it is and testing yet we -- show wet it's gonna drop pot gates. All -- to have these going to get are long gone thing's gonna stop dying on. Oh the phone's not got much memory so it so that it gets hot sudden bonds updates. I'm hoping will hop and it's -- be at all -- to start drop in pockets but it people. But it won't stop delaying the the net that traffic books -- it does not then he's gonna study notes the idea useless."

" the issues is good -- put in place in between. Your target and the switch and not necessarily in between the switchers and the routers. You might also find more easily. Depending on your network. Closet or did senator would not. So I gotta ask what are where is the website where can we get the code play with that sought on our own stuff and and discuss it."

" They all coda it's going to be go we're -- to -- to all slosh into sets up. Aren't actually get a hold me. The ninja opt you know the --"

" Great and we've set up the interceptor forms they're right there next that they Gaza got forms. And -- you guys to come out and you know share your experiences playing with the code in kind of come up with some ideas for some new features to keep in mind you know. -- you we'll put this in place on on your target and their office is only open from nine to five two words you can law again and you plug your on the network. Right. Okay so fond 2.0 beta any any ideas that we've got a hold of the hardware it's just like the fun plus but we have a USB port."

" Yet and -- let's -- put the video conferencing -- box working so you're speak hope. But it video IVRoots eighties side notes aren't you XP XX. -- whack com they can drop it anywhere. You bytes doesn't sound. Vehicle that saying. Wheel drive is just. Storage device and put on. The networks so I don't click and you've got wireless in the quiet seek the fake pops out into it. Aunts. And you would buy it is the viewers people quit we're open to ideas he could suggest a big codes do it. Too wired or wireless. -- you speak what's let's not."

" Definitely I mean some things to come to mind our fight the Bluetooth stuff like that so we want to hear your. Suggestions so you know hit up did you ninja had a feedback and let us know. Robin thanks so much for coming on that we got have you on again in the future can we need to talk about ear trumpet all of the other -- fully -- on there."

" Yeah definitely. It's it's -- they threw it on and on. -- It's I'd like to take a moment to thank one of our wonderful sponsors that keeps us on the air Netflix. With Netflix you can rent over 90000 titles online including lots of Blu-ray. With free shipping both ways to your home and back they now have over forty shipping centers almost all deliveries happen in just one. That's what plans at night night and doesn't remember you can get a notice."

" Check it out at WWW."

" Forget about it."

" War."

" a pack five is brought to you by godaddy. Netflix. In Squarespace."

" Money and take him out. Mr. Wright once again my name is back. Right. Well. Let's forget. To whom it may concern. -- The fabulous mr. Wright. Recently purchased. A bottle of the troops. About an hour after the taking the supplement. I happen to develop a rather humongous. Scratch that. A rather large."

" Enter."

" Yes I took the ointment. No it's not working. Its its its. Hey got flower delivery for Becky Stewart. Excellent. I -- admire."

" Exciting. This little guy."

" Albright and was forgot this is the admirer monkey goes with the flowers. It what's what he had."

" It plugs into your computers Internet and when you go to your profile page every secret admirer unlike FaceBook he lights up and play the song for you."

" I've honestly. Not work. Yakking cell. We're can be -- nobody uses veto. -- Eight oh. Oh yeah."

" Okay less often I will stop yelling at you when you actually prescribe me something to work. Not it's my fault. That's -- she finds it. -- If you seen my bowl cream you know the one for my extra large. --"

" This month's Lan party is insurgency monitoring infantry combat we're playing over and -- agency dot Hak5 dot org. On March 28 at 3 PM eastern. If you're not till indisputable insurgency thank you can -- of -- that Squarespace dot com and vote for your favorite -- game. And I have to thank our wonderful sponsors Squarespace. Squarespace is a publishing system for anyone looking about a blog portfolio or any kind of website they powering large businesses to blogs. And Squarespace gives the opportunity to. Build pages that are just as powerful and flexible as those of the big dogs. And you can go to Squarespace dot com right now for a two week free trial membership. And you can see use code Hak5 that's H a K five for 10% off the life of your service."

" Interceptors the network tapped the -- a wired connection over Rogue wireless access point. Well in May have become significantly paranoid about pineapples and no wireless traffic too often we take for grant the security of a wired networks. Whether -- home work or abroad the prospect -- in in the middle attack poses a significant threat especially deal with an encrypted communications. Hackers and pen testers -- years have exploited the nature of the network by becoming the man in the middle using techniques such as our cache poisoning. And network administrators have you sniffing tools like wire shark in conjunction with -- network -- to troubleshoot congestion. But these tools and techniques require a level of access and presence that isn't always viable. So what if there were a device that could see it in line on a wired network passively monitoring the packets. And what of this device came with the road wireless access point that an attacker could access to initiate a private tunnel and tap into that traffic. This device would be small with the ability to sit behind the network won't play. Or inciting Q plus she with the ability to social engineer secretaries. Or maybe it could attach to the back of the PC with a phony telephone company logo. And all the wild the attacker could connect wirelessly from the convenience of a black van parked outside the corporate office and here past the file without notice. Unobstructed to latency time to live with the same wireless security bill to keep the black -- out. This little device could stand stealth -- from nine to five then at the drop of the hat from passive to active stroll in the network from the inside out. The devices speak of is none other than Robin woods interceptor and today we'll be building one bad little monkey in the middle. So let's get started. First we'll need a wireless -- with two or more ethernet ports capable of running our favorite embedded at less -- to be RT. For this will be using it goes so hackable on plots. These little guys were designed and manufactured by act on and -- flash from custom font firmware. The basic idea is that they let you share your Internet telephone heiress an intern and borrow a cup of packets from other scenarios while ago. It's a noble idea and great community and we're happy to see these little creatures in the wild. But as always we've got plans for this little routers. He's in the power of fair use in the ancient art of ninja hacking skills will unlock this little from Tara. Instill interceptor stuffed inside a plus monkey and weaponized a little guy. But first a quick look under the hood. One plus runs on a lock down version of OW RT. Requires seven full to power and runs on a 183. Megahertz -- processor. At sixteen megs of ram it makes a flash tool 10100 megabit ethernet ports and speaks attitude at eleven B and G. He also sports a serial port which is great from breaking an omni directional one point five dvi antenna. And the standard RPS and they connector for more powerful intact. Now let's get hacking first -- computer emergency -- some ethernet cables and some special software. We'll be doing this in Linux however you can do the same in windows or Mac as long as if pearl SCH -- CP opened VP NT FT PD. And TCP jumper wires -- All of the packages the software used in this are available did you -- dot org or Hak5 Wiki. Before we begin we'll need a copy of open to the RT eight points here than nine for a Ferris. VMware and -- in May and root out squash a fast NT FT PD typically found -- slash T ftp built. Now will begin by bringing up the ethernet interface on a PC as 190 -- one got 254. Connecting Internet cable between the PC and fun plus easily import and run -- it to PL 1921681. Someone might want twit connected to read do via Tel net war one to flash the firmware. So issue -- and it. Then load the kernel from T ftp. With load attack our tech B. Percent free Menlo. Open to the RT there us -- those in May and bright the image with this create tech T. Zero X 800. 41000. -- 841000. Via live next stop being dot -- this takes a while so want to take a break and have a -- they're good for you. Next load the file system from T ftp -- load -- car tax -- percent premium low. Open to the RT -- terrorist tack room dot squash FS and bright -- image with this create tech -- Zero X six F 0000. -- fast. This part takes a long while considering banana smoothie in a blender mix bananas ice milk and your favorite yogurt and all right once a file system is written will need to configure -- issue -- configure an answer true to the first question. Then answer the following the script. Has slowed -- LVM. The next obvious and I L seven exact. One a 22 Pritzker time -- no boot peak network configuration. No Gateway IP address of local IP of 192 don't want to take that one one. A network mask of 255255. 255 zero. The default server IP set to 190 you don't want succeed at one point 254. A consul baud rate of 9600. And the GDP report at 9000. Tell red dude not to force consul for special to bug messages not to -- bug network news and finally go ahead and update the non volatile configuration. Issue reset and the connection we'll close that from."

" Our PC will go ahead -- 19 -- don't want to take 11. We should receive replies shortly. Tel net to when ninety don't want to -- that one one and will be greeted by open WRT kamikaze show. Is she passed WTO -- monkey business twice. Now exit from power PC will go ahead and necessary to revert to brute 190 don't want succeed one one. After accepting certificate. Once again be greeted by opened of the Ortiz show. Now we'll open another terminal on -- PC and navigate to the directory containing interceptors required packages. Will be as seeking these files over to the fun plus in slash TMP. But he could also -- these packages from a local HTTP server using W gets. SEP start I PK 2190 Dublin succeed one -- one and slash TMP. Now back over on the fun plus we'll use OP KG to install all of the packages and slashed -- Finish off your banana smoothie or came -- on the -- bills Leo lid open SL AZ lid -- VPN live peaked cap and live Tina are installed and configured. You may also want to include the nano packages and any other goodies like nmap. Next we'll let that the wireless configuration. The important part here is to set disabled zero. Give the Wi-Fi interface in a society and seventies WPA. PS KTU. We'll also want to edit the network interface. Here we set the lynch static Britain's with a -- of 19 to -- once it's seen that one one and an interface name of -- zero point zero. The win will be called at zero point one. Now remove all entries from at C slash Arce got. HT TPD or -- mask. Back on our PC will want to grab the latest version of interceptor from did you do about work. Unpacked the tar and as he PD interceptor -- package to the fund plus in -- TNP. Switch back to the fun plus and instill interceptor with okay KG. Now we can start interceptor by issuing -- at C slash -- such interceptor. Start. From our piece he will need to create open VPN -- If you're not familiar with hoping geeky inning -- generation you can find more details on our forms. We start by copying the easy RSA files who are working directory an editing bars. Tweak the sample configuration and will be all set to build the keys. Issue bars clean install and build CA. Next issue build key server server. Then build key client one and build dot DH at this point you should have a bunch of -- certain key files. Only to a CP client one does hurt Clinton won the key and see aid concert 190 don't want to take a one to one. In slash interceptor slashed open VPN slash client. Now created your -- concerts where -- interceptor startup script is located and copied DH 1024 dot -- Server to assert server that key. And see a -- there. Finally were ready to test interceptor. Plugged the wind pored over from there into the switch and the limp or into a spare computer. Set it to run -- constant pinging or any other sort of traffic. This is the target that will be eavesdropping on shortly. Now back toward PC will need to connect the -- for wireless so let's created to -- PA supplicant config file with interceptor is there SS ID. And monkey business as -- password. Once that's complete issue to EPA's applicant attack DW EXT. Attack I 20 taxi. Like configuration files. Now that we're associated we need to manually set RIP address to ten 255. 255 to 253. -- attend -- 255 -- to touch 254. To ensure that interceptors running and then run the startup script. Open VPN connection should -- and you'll be asked for the root password when interceptor is ready to start team and longer. Now in new terminal run -- config and verified that -- zero is up. Tell TCP -- to listen to taps Euro or fire up -- you should now see all of the traffic between your target computer and the switch. That's it you ready to toss it in a monkey weaponized little primate and star pirating some packets -- on -- San wireless. When you're done with you passing attack go ahead and scan the network assign an IP address that's our hacking from the inside out. Or send your monkey of the Hak5 forms for more information about fund plus months. Interceptor extensions or other platforms interceptor supports."

" This week's trivia question it is what -- monkeys have the pleasure of being shot and the space atop an -- eighteen missile in 1959. Submit your answer to Hak5 dot org slash trivia and entered to win this week's given what -- and I have to thank our sponsor godaddy. Think smarter than the rest prove it and you could win big it's more space from godaddy.com has changed the way you use the Internet the way you blog the way you do business. The way you live your life. Create a blog or video story that shows how. You might just wind when he 5000. Dollars in cash prizes and free smart space for life. So head over to godaddy.com. Slash SS contest and now. Don't have -- smart space see what it's all about and save an additional 15% off your April 15 2009. Make sure use Kennedy space fifteen."

" To today we had pleasure having our friend Robin wood on brought in last time we saw is that an aircraft carrier we're talking my the other dog got. What's been up since. I think it we've and it's very com. The bush would look phones. Yeah that's your forte it seems. This particular -- there were talking about today interceptors based on me on plus. -- may -- you can explain to us some of the features of interceptors kind of how. It came to be."

" Rattled the insects. And that's what I could remember -- can buy it from let's talk column. When we -- but foam close to wired network counts of wireless exit will. Would be good idea -- network top and so since then -- playing with dates. I'll look below where it is say wireless why its network so. The idea race. Get a phone in talk in line and it its network. All the dates going across the two why knicks get spots on it through the wireless. And can then be sniffed all's well that -- so well that's not so much else."

" I think the idea of having that Rogue access point that's just sitting in line is actually beautiful maybe Khatami some of the software that that's involve the packages that actually. Make it all come together."

" Well initially the idea was just to use that IP tables aren't close all the -- there was going across the bridge on the phone. -- soil -- so they know he's in the media stunt that's. -- I don't look -- IP tables couldn't get it it working. So outside looking -- so its -- lot of people. I on the best thing we will wait world's package called the Malacca which she's from. Not seeing brochure thinks that this guy does set Stoltz. And what not to policy -- to expect XIDs sake Photoshop bullets. So sucks off. This floating all the stuff they call the rage -- soup Nazi era. -- it's an excellent stairways. Local but I couldn't get it working. Again and -- not asking it's on with some help from not say on the guy on the -- list. Heats. A box that resembles. We finally can the idea all of schooling to date so of -- yet. Eight -- and a YOX. Beat the X. I would put it all web sites now I've on the city cool it's Beck's way of giving it the -- I will wait and I lost a lot of they. So basically. Traffic across the wide in space he's flown on suit. Hey open began space. Sent through La -- wireless. And open he can suddenly threatened since the it's. Puts -- you didn't face that you can walk twit T Speedo all white shop."

" Now tell me a little bit about the hardware only of course your forte -- some fun we're doing the fun plus. It's -- harder because it'll run open WRT we get a nice that there's chips that. But is that is that all necessary is is this something that you can actually put together and another piece of hardware."

" I -- well a light Kelly yes again there are no cheese it's true and UH I was and the -- opt. So theoretically it should work on any. Device at least it's too quiet settings faces on the wireless. There will open the say. I'm gonna just try to at the moment but it's. It sold to stop the puck so don't see why it wouldn't work."

" So Robinson's we have 200 megabit ethernet and a 54 megabit wireless what's gonna happen there when there's a lot of traffic."

" So the reverend fully tested yet it's the sudden so it will be yet limitations the list. Of state or so -- make choppy coastal why it's a box and that it -- well what are the loyalists. You technical talk about the and open geek gadget she's gonna slow things down debates. I could it is and testing yet we -- show wet it's gonna drop pot gates. All -- to have these going to get are long gone thing's gonna stop dying on. Oh the phone's not got much memory so it so that it gets hot sudden bonds updates. I'm hoping will hop and it's -- be at all -- to start drop in pockets but it people. But it won't stop delaying the the net that traffic books -- it does not then he's gonna study notes the idea useless."

" the issues is good -- put in place in between. Your target and the switch and not necessarily in between the switchers and the routers. You might also find more easily. Depending on your network. Closet or did senator would not. So I gotta ask what are where is the website where can we get the code play with that sought on our own stuff and and discuss it."

" They all coda it's going to be go we're -- to -- to all slosh into sets up. Aren't actually get a hold me. The ninja opt you know the --"

" Great and we've set up the interceptor forms they're right there next that they Gaza got forms. And -- you guys to come out and you know share your experiences playing with the code in kind of come up with some ideas for some new features to keep in mind you know. -- you we'll put this in place on on your target and their office is only open from nine to five two words you can law again and you plug your on the network. Right. Okay so fond 2.0 beta any any ideas that we've got a hold of the hardware it's just like the fun plus but we have a USB port."

" Yet and -- let's -- put the video conferencing -- box working so you're speak hope. But it video IVRoots eighties side notes aren't you XP XX. -- whack com they can drop it anywhere. You bytes doesn't sound. Vehicle that saying. Wheel drive is just. Storage device and put on. The networks so I don't click and you've got wireless in the quiet seek the fake pops out into it. Aunts. And you would buy it is the viewers people quit we're open to ideas he could suggest a big codes do it. Too wired or wireless. -- you speak what's let's not."

" Definitely I mean some things to come to mind our fight the Bluetooth stuff like that so we want to hear your. Suggestions so you know hit up did you ninja had a feedback and let us know. Robin thanks so much for coming on that we got have you on again in the future can we need to talk about ear trumpet all of the other -- fully -- on there."

" Yeah definitely. It's it's -- they threw it on and on. -- It's I'd like to take a moment to thank one of our wonderful sponsors that keeps us on the air Netflix. With Netflix you can rent over 90000 titles online including lots of Blu-ray. With free shipping both ways to your home and back they now have over forty shipping centers almost all deliveries happen in just one. That's what plans at night night and doesn't remember you can get a notice."

" Check it out at WWW."

" Forget about it."

mari1ee

Started discussion: March 18, 2009 @ 12:17pm GMT

Episode 505 - Introducing Interceptor: The network tap and rogue wireless access point [Discussion]

The perfect primate for pen testers is none other than network monkey. Introducing Robin Wood's Interceptor -- on this episode we hack the Fon and turn it into a network tap and rogue wireless access point. Sniff the LAN from across the street or hack the network from the inside out! Learn how Network Monkey Pirates your Packets today!

Watch or download the episode now!

computoman
8 months ago
very interesting.....
masterevilace
8 months ago
Love the jeremy reference!
Snubs
8 months ago
In reply to masterevilace:
Love the jeremy reference!



Thanks :D I hoped people would get that PP ref.
dirtyhat
8 months ago
Ok Im getting most of it but there's one part thats not working for me :(

no matter what I try it always fails... hope you can help me
.
.
.
.
.
how much milk do I add to the banana smoothie? ;)
computoman
8 months ago
Most secretaries I know are pretty computer saavy and would not fall for the monkey bit. Thought it is worth a try.
View all 5 comments