Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 27 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Cain & Abel v2.8 Released
EH-Net
May 21, 2013, 10:27:21 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Cain & Abel v2.8 Released  (Read 11848 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: October 19, 2005, 10:58:25 PM »

Read the new features list at http://www.oxid.it/index.html.
Download your free copy at http://www.oxid.it/cain.html.

In addition to Cain & Abel, Oxid also features the following tools:

  • IRS scans for IP restrictions set for a particular service on a Host. It combines "ARP Poisoning" and 'Half-Scan' techniques and tries totally spoofed TCP connections to the selected port of the Target. IRS is not a port Scanner but a 'valid source IP address' Scanner for a given service.
  • sTerm is a Telnet client with a unique feature. It can establish an entire bi-directional Telnet session to a target host never sending your real IP and MAC addresses in any packet. By using "ARP Poisoning", "MAC Spoofing" and "IP Spoofing" techniques sTerm can effectively bypass ACLs, Firewall rules and IP restrictions on servers and network devices. the connection will be done impersonating a Trusted Host.
  • cPfPc (Cisco PIX Firewall Password Calculator) produces the encrypted form of Cisco PIX enable mode passwords without the need to access the device.
  • ArpWorks is an utility for sending customized 'ARP announce' packets over the network. All ARP parameters, including the Ethernet Source MAC address (the phisical address of your network card) can be changed as you like. Other features are: IP to MAC resolver, subnet MAC discovery, host isolation, packets redirection, general IP confict.
  • CredDump is an utility that dumps passwords from Windows XP/2003 user's credential files and shows them in they're cleartext form.
  • Winrtgen is a graphical Rainbow Tables Generator that supports LM, FastLM, NTLM, MD2, MD4, MD5, SHA1, RIPEMD160, MySQL323, MySQLSHA1, CiscoPIX, SHA-2 (256), SHA-2 (384) and SHA-2 (512) hashes.

Share your experiences with Cain & Abel or any of the tools listed above by starting new topics.
Logged

CISSP, MCSE, CSTA, Security+ SME
spyder2535
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #1 on: December 06, 2007, 07:50:34 PM »

I have seen a video tutorial on ARP poisoning with Cain and read Mao's flash tutorial.  In Mao's flash tutorial he talks about redirecting traffic from an outside LAN.  However, I cant find a tutorial that goes into more detail about it.  Can someone tell me if there is a tutorial somewhere that has a step by step of how to make Cain work outside of your own LAN?

Thanks,
spyder
Logged
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #2 on: December 07, 2007, 01:56:35 PM »

You can not do this because ARP is layer2 and your subnet is the only place you can router MAC addresses. You can use some of the other features in Cain over the internet but not ARP poisoning. ARP poisoning will only work in a layer2 network. The only option to go past you own LAN is if Mao figures out how to get Winpcap to work in Able and allow remote installation of Able to relay the ARP info over other subnets.

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
Negrita
Sr. Member
****
Offline Offline

Posts: 299



View Profile
« Reply #3 on: December 07, 2007, 04:07:39 PM »

You can not do this because ARP is layer2 and your subnet is the only place you can router MAC addresses.

This is incorrect. You evidently forgot about Multipoint Layer 2 MPLS VPNs (AToM). BTW does anyone here have experience in doing ARP poisining over MPLS?
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #4 on: December 07, 2007, 06:29:08 PM »

With MPLS or Metro Ethernet services it is true because it's a layer2 service by the ISP. smiler to a Layer2 VPN but the point I was trying to make was ARP poisoning works in the MAC domain your in unless you have a device to repeat or encapsulate the layer2 MAC addresses to forward them to the next network. Other issues you might see in an MPLS/Metro Ethernet service is being restricted by VLAN. I have requested Mao to find a remote (Able) solution to access other subnets with the ARP traffic and tables but to do this you will need some way to bounce or repeat the mac domain tables so Cain can alter them to force the traffic to you NIC.

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.