Results 1 to 4 of 4

Thread: Ettercap, ARP Poisoning in VMware

  1. #1
    Just burned his ISO
    Join Date
    Mar 2010
    Posts
    8

    Default Ettercap, ARP Poisoning in VMware

    Hello,

    i hope someone can help me. I use Backtrack 4 in a VMware. On the VMware settings i set the network adapter to briged. I followed the tutorial of g0tmi1k "Stripping SSL & Sniffing HTTPS" (big thanks to him for this very good tutorial). The VM runs on a laptop connectet to the LAN with wireless card. When i start the network i type in in the shell: start-network, wicd-client.

    Well, i followed exactly the tutorial of g0tmi1k but the victim machine loses the connection to the internet. So i cant sniff. I dont know why. The Router ARP Table is not fix.

    When i run wireshark i see an ARP frame where it tells "Mac duplicated". Maybe the router sees that there are two same mac addresses?

    Or is there a problem with ettercap and vmware? Maybe because i set the network adapter to briged?
    Maybe someone can help me.
    Thank you.

  2. #2
    Junior Member creepykrawler's Avatar
    Join Date
    Jan 2010
    Location
    USA
    Posts
    56

    Default Re: Ettercap, ARP Poisoning in VMware

    Have you edited the /etc/etter.conf file?
    "Failing to plan is planning to fail"

  3. #3
    Just burned his ISO
    Join Date
    Mar 2010
    Posts
    8

    Default Re: Ettercap, ARP Poisoning in VMware

    Hi,
    thank you for your reply.

    Yes i edited the etter.conf.

    Well, i did some research with google and i found other users with the same problem, but it looks like there is a solution for this problem. A wireless usb adapter can solve it.
    Im just wondering why it isnt possible. I know that Vmware doesnt allow to set your network card in promiscuous mode. I found this out when i used wireshark. In BT3 i lost the lan connection when i runned wireshark in promiscuous mode, but i am not sure if ettercap sets the network card in promiscuous mode.

    I ordered a wireless usb network adapter today so i will post here again when the arp spoofing works with the adapter.

  4. #4
    Just burned his ISO
    Join Date
    Mar 2010
    Posts
    8

    Default Re: Ettercap, ARP Poisoning in VMware

    Hello,

    well, i got my usb network adapter and it works fine now. The victim machine does not lose anymore the i-net connection. It was not the promisc mode of ettercap since i deactivated it before i started the attack. So i still dont know why it does not work with the integrated network card.
    But, that is not a problem anymore .

Similar Threads

  1. Ettercap With ARP Poisoning
    By micole in forum BackTrack Howtos
    Replies: 24
    Last Post: 04-23-2011, 12:33 PM
  2. ARP Poisoning 101 (Not sniffing info...)
    By Whiskey in forum Beginners Forum
    Replies: 12
    Last Post: 07-15-2010, 02:12 AM
  3. Ettercap - No poisoning between client -> host
    By Dishwasher in forum Beginners Forum
    Replies: 2
    Last Post: 03-06-2010, 06:15 PM
  4. Replies: 6
    Last Post: 02-22-2010, 01:51 AM
  5. ettercap
    By fragolicous in forum Beginners Forum
    Replies: 3
    Last Post: 02-16-2010, 03:58 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •