Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 14 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008s
chicagocon2008s_125x200.jpg
ChicagoCon 2008s
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow Wilsonarrow [Article]-Video: Man-in-the-Middle Attack on MySpace with Cain
Ethical Hacker Community Forums
July 04, 2008, 05:29:21 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Podcasts and slide decks from ChicagoCon 2008s talks coming soon! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Video: Man-in-the-Middle Attack on MySpace with Cain  (Read 15419 times)
0 Members and 3 Guests are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2146


Editor-In-Chief


View Profile WWW
« on: March 14, 2008, 11:42:22 AM »

This one uses MySpace as the hypothetical target. Expect many more of these from Brian, our resident Cain expert. Well done my friend.

Permanent link: [Article]-Video: Man-in-the-Middle Attack on MySpace with Cain

Quote

By Brian Wilson, CISSP, CCNA, CCSE, CCAI, MCP, Network+, Security+, JNCIA

Last year at ChicagoCon 2007, Brian Wilson gave a great talk entitled "Cain & Abel: Windows Can Hack, Too!" Although the presentation and audio recording of the talk can be downloaded from the ChicagoCon  Media Lab
 2007 Evening Presentation Files, I had totally forgotten to publish his videos. Just in case things didn't go as planned during the live event or his laptop crapped out on him, Brian made a video of the MITM attack he demonstrated using Cain. They made it on the DVD passed out to the attendees, but unfortunately not in his column... until now!


Although we often talk about this incredibly versatile tool here on EH-Net, for the uninitiated...

Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols.



Thanks again Brian. Please offer Brian your thoughts and also requests for additional Cain vids.

Don
« Last Edit: March 14, 2008, 12:32:24 PM by don » Logged

CISSP, MCSE, CEH, Security+ SME
RoleReversal
Sr. Member
****
Offline Offline

Posts: 305


View Profile WWW
« Reply #1 on: March 14, 2008, 11:48:28 AM »

Brian,

nice video, I've had Cain&Abel on my 'Must look at' list for a while. Think you've just jumped it to the top of the queue.

Thanks
Logged

A little bit of sanity:
http://www.infosanity.co.uk
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2146


Editor-In-Chief


View Profile WWW
« Reply #2 on: March 14, 2008, 03:36:47 PM »

Sir Brian has never made it to diggs front page or slashdotted. Let's help make it happen for him.

http://digg.com/microsoft/Video_Man_in_the_Middle_Attack_on_MySpace_with_Cain

You have 24 hours to do your part!!

Don
Logged

CISSP, MCSE, CEH, Security+ SME
pseud0
Full Member
***
Offline Offline

Posts: 131



View Profile
« Reply #3 on: March 15, 2008, 09:09:35 AM »

Sweet mamba-jamba!!  Slashdotted!!
http://it.slashdot.org/article.pl?sid=08/03/15/1242252&from=rss
Logged

CISSP, CISM
RoleReversal
Sr. Member
****
Offline Offline

Posts: 305


View Profile WWW
« Reply #4 on: March 15, 2008, 09:27:05 AM »


w00t!

Hows the site holding up under the legendary /. effect Don?
Logged

A little bit of sanity:
http://www.infosanity.co.uk
ChrisG
Hero Member
*****
Offline Offline

Posts: 923


View Profile WWW
« Reply #5 on: March 15, 2008, 11:15:01 AM »

thanks for the link and the reminder why i dont read slashdot, most of those replies are pure garbage.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2146


Editor-In-Chief


View Profile WWW
« Reply #6 on: March 15, 2008, 11:24:18 AM »

So far so good.

Congrats, Brian. Helluva week for you my friend. Your good fortune is well deserved.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
slimjim100
Sr. Member
****
Offline Offline

Posts: 351



View Profile WWW
« Reply #7 on: March 15, 2008, 12:49:26 PM »

Thanks everyone!!!!  Don called me on my Cell and told me I was slashdot'ed. I was on a 3 mile hike with my kids for Cub Scouts... I was like wow and I told some of the other fathers out on the trail and they where like what is slashdot and I said never mind. lol

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
ChrisG
Hero Member
*****
Offline Offline

Posts: 923


View Profile WWW
« Reply #8 on: March 15, 2008, 09:41:17 PM »

that's awesome
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
slimjim100
Sr. Member
****
Offline Offline

Posts: 351



View Profile WWW
« Reply #9 on: March 15, 2008, 10:11:49 PM »

Wow over 8,000 hits to the video in 12 hours thats crazy! I hope Don's hosting company does not charge him to much for the extra bandwidth. Anyway thanks again for all of you guys/gals support. I will be doing a newer live demo of Cain & Able at Chicagocon this year and if all goes right I hope to show you how to own and record VoIP calls, Take over Cisco routers, Crack WEP with packet injection (yes in windows) and so much more. Cain is truly a good place to learn a lot of hacking and auditing skills on a Windows PC.

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
subbukl
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #10 on: March 22, 2008, 08:07:55 PM »

dont you think arpspoof and etherial is much simpler for this ?
~
Logged
ChrisG
Hero Member
*****
Offline Offline

Posts: 923


View Profile WWW
« Reply #11 on: March 22, 2008, 09:23:20 PM »

no
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
slimjim100
Sr. Member
****
Offline Offline

Posts: 351



View Profile WWW
« Reply #12 on: March 23, 2008, 11:05:08 AM »

Well I do like Ethereal but only after I have a good APR with Cain going then I can look at all traffic on a subnet for trouble shooting. It's like making a mirror or trunk port on a switch that might not have management features.

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2146


Editor-In-Chief


View Profile WWW
« Reply #13 on: April 15, 2008, 08:31:14 PM »

Congrats, Brian!!

100,000 Page Views!!

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.054 seconds with 23 queries.
 
BackTrack2 VM w/ MSF3

Get it here NOW!

Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008s_125x200.jpg
ChicagoCon 2008s


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008s_125x200.jpg
ChicagoCon 2008s
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.