WINDOWS 7 - SNIFFING
- Layout for this exercise:
data:image/s3,"s3://crabby-images/b874e/b874e63271686979b4dd2a1ac265513c13d53e5a" alt=""
- Metasploit
provides the module sniffer, what be loaded from a meterpreter
session:
data:image/s3,"s3://crabby-images/5b525/5b525de4c08471dcb5939354328db43ac330b24d" alt=""
- Checking
how many interfaces are available for sniffing, let's take one with
parameter "usable:true":
data:image/s3,"s3://crabby-images/fd87a/fd87a99ca12d46be085e8eddc656f7da622806aa" alt=""
- The sniffing process starts on interface 2, allocating 10000 packets to the buffer:
data:image/s3,"s3://crabby-images/21215/21215d644b90ac134f5eb931e9fe3312402f13bb" alt=""
- Some traffic is generated, for instance pinging from the attacker Kali to the victim Windows 7:
data:image/s3,"s3://crabby-images/c9ca9/c9ca911971444cc27859e976e730ff6bf3e781ef" alt=""
- Statistics of the sniffing process:
data:image/s3,"s3://crabby-images/e503b/e503b796e441157e1b47864a02bba62b5b016fe5" alt=""
- Captured packets can be dumped to a file with pcap format, for instance let's name it readable_with_wireshark.pcap:
data:image/s3,"s3://crabby-images/a8d54/a8d54adf90651b68a1aa4fbaccc64416d308472e" alt=""
- Stopping the sniffing process:
data:image/s3,"s3://crabby-images/8760b/8760bf15f3da6322cc5fa0e2a4dfb948e8693b3e" alt=""
- From
another console, captured packets can be read with Wireshark
application:
data:image/s3,"s3://crabby-images/ea9e6/ea9e6c9a25364202d137da3d7a7fdd59111a5e22" alt=""
- Wireshark
shows all the traffic generated by the ping's between the attacker
and the victim:
data:image/s3,"s3://crabby-images/a8e0d/a8e0d1f27ab8bb1c2fe2b7c1d9bd50f0cd2bd016" alt=""