Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 60 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow Stealthing the Ether
EH-Net
May 19, 2013, 01:37:28 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Stealthing the Ether  (Read 4609 times)
0 Members and 1 Guest are viewing this topic.
str8jack3t
Newbie
*
Offline Offline

Posts: 7


View Profile
« on: June 29, 2011, 11:54:35 AM »

A friend of mine was complaining about how he thinks somebody is tapped into his Wi-Fi.  I found out after looking into it, that he's using WEP...that's sad in itself.  Secondary he's got the default admin/password on his router admin page, not so smart, but not surprising.

When I logged into his router admin, I noticed several PC's named the same as his...I guess masking them on first glance?? Obviously the MAC addresses were different.  So I assume he is getting tapped for free Wi-Fi, but it got me to thinking:

1) What would you do to mask yourself in this scenario?
2) Was naming the PC the same as his an attempt to mask?

I'm new in this type of arena and now I'm interested like crazy and would love to put myself in their shoes to see the angle...like reverse engineering.  Let me know how you would cover your tracks or post links referencing this scene.

Thank you all in advance!!
Logged
El33tsamurai
Full Member
***
Offline Offline

Posts: 192


View Profile
« Reply #1 on: June 29, 2011, 12:01:35 PM »

Someone once told me they can tell me and I will remember for 10 minutes or they can tell me to go look it up and I will remember it forever, so I going to tell you the same hit up google and do some research on how to mask yourself and come back and tell us about it.
Logged

CCENT, A+, Network+, Security+
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #2 on: June 29, 2011, 12:12:05 PM »

You can also modify the MAC address to match another machine on the network.  This will hide your presence, making it look like a machine that the wifi owner believes is supposed to be on the network.  This also has the added bonus of bypassing MAC filtering, if configured.
Logged

GSEC, eCPPT, Sec+
El33tsamurai
Full Member
***
Offline Offline

Posts: 192


View Profile
« Reply #3 on: June 29, 2011, 12:15:34 PM »

Take the next step and you have arp poisoning.
Logged

CCENT, A+, Network+, Security+
packet.Wire
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #4 on: June 29, 2011, 12:23:00 PM »

Changing your mac address to something that doesn't look suspicious is one of the ways that you'd do it. You wouldn't want to change it to 00:11:22:33:44:55 because that'd stand out too much. Most home users, and corporate for that matter, don't keep track of mac addresses in their possession.
Logged

CISSP CCNP CCSP Sec+
El33tsamurai
Full Member
***
Offline Offline

Posts: 192


View Profile
« Reply #5 on: June 29, 2011, 12:25:01 PM »

O but they should.
Logged

CCENT, A+, Network+, Security+
str8jack3t
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #6 on: June 29, 2011, 01:53:48 PM »

El33tsamurai - HAHAHA, love it!  I will take your advice boss! Thank you.

packet.Wire - Excellent.  I have a couple PC's I can play with.  Will do some research and see how it goes.  Thank you!

lorddicranius - Thank you for that!!!

Time to rake the net!!
Logged
El33tsamurai
Full Member
***
Offline Offline

Posts: 192


View Profile
« Reply #7 on: June 29, 2011, 02:00:44 PM »

With an answer like that you will do well in this field!  If a person say WTF was that, so stupid! Will go no where in this field.
Logged

CCENT, A+, Network+, Security+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 2.897 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.