Page 1 of 3 123 LastLast
Results 1 to 10 of 23

Thread: easy-creds 3.6 released

  1. #1
    Senior Member
    Join Date
    Dec 2010
    Posts
    127

    Default easy-creds 3.6 released

    http://sourceforge.net/projects/easy-creds/files/

    v3.6-BT5 11/08/2011

    New Attacks:
    - DNS Spoofing Attack
    - AP Client deauth

    New Prereqs:
    - SSLStrip Updates
    - Edit etter.dns

    Enhancements:
    - Exit will now clean up attack before exiting
    - Less input required for creating dhcp.conf file

    Fixes:
    - Route add for wireless attacks specified wrong interface and would fail
    - Dsniff, URLSnarf & SSLStrip were listening on wrong interface for wireless attacks

    Instructional Videos:
    http://www.youtube.com/user/Brav0Hax

  2. #2
    Good friend of the forums comaX's Avatar
    Join Date
    Feb 2010
    Location
    Paris, France
    Posts
    338

    Default Re: easy-creds 3.6 released

    Thanks for the release, I sure will give it a try

    Where is it regarding integration to the repo ? How about that speech you had to do ? Done yet ? It would be nice hearing news, maybe in another thread

    Keep up the good work !
    Running both KDE and GNOME BT5 flawlessly. Thank you !

  3. #3
    Member
    Join Date
    Sep 2010
    Location
    Eastern Island
    Posts
    96

    Default Re: easy-creds 3.6 released

    yahu! tnx..

  4. #4
    Senior Member
    Join Date
    Dec 2010
    Posts
    127

    Default Re: easy-creds 3.6 released

    @comaX I submitted an "upgrade" via redmine to BT. I am not sure how long the process takes there. Should be a month or so I assume. I did give a talk at Hack3rcon, you can see it on my YouTube page I think I linked to it. Still waiting to hear back from Black Hat Abu Dhabi. Doubt they'll accept it, but I submitted for Shmoocon as well so fingers crossed.

    Also, even bigger news me and a few other people have officially taken over ettercap development with Alor & Naga's blessing. First new release in 6.5 years will be coming out December 2nd. All bugs fixed and currently being tested on multiple OS's. Awesome stuff!

  5. #5
    Just burned his ISO
    Join Date
    Jan 2011
    Posts
    14

    Default Re: easy-creds 3.6 released

    Quote Originally Posted by ericmilam View Post
    http://sourceforge.net/projects/easy-creds/files/

    v3.6-BT5 11/08/2011

    New Attacks:
    - DNS Spoofing Attack
    - AP Client deauth

    New Prereqs:
    - SSLStrip Updates
    - Edit etter.dns

    Enhancements:
    - Exit will now clean up attack before exiting
    - Less input required for creating dhcp.conf file

    Fixes:
    - Route add for wireless attacks specified wrong interface and would fail
    - Dsniff, URLSnarf & SSLStrip were listening on wrong interface for wireless attacks

    Instructional Videos:
    http://www.youtube.com/user/Brav0Hax

    thanks for the update , one question do you think this script could be used on maemo n900 ??

  6. #6
    Just burned his ISO
    Join Date
    Apr 2010
    Posts
    14

    Default Re: easy-creds 3.6 released

    I dont know if im the only one but, i get this errors on sslstrip when i poison the network:

    sslstrip 0.9 by Moxie Marlinspike running...
    Traceback (most recent call last):
    File "/pentest/web/sslstrip/sslstrip.py", line 105, in main
    reactor.run()
    File "/usr/lib/python2.6/dist-packages/twisted/internet/base.py", line 1170, in run
    self.mainLoop()
    File "/usr/lib/python2.6/dist-packages/twisted/internet/base.py", line 1182, in mainLoop
    self.doIteration(t)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/selectreactor.py", line 140, in doSelect
    _logrun(selectable, _drdw, selectable, method, dict)
    --- <exception caught here> ---
    File "/usr/lib/python2.6/dist-packages/twisted/python/log.py", line 84, in callWithLogger
    return callWithContext({"system": lp}, func, *args, **kw)
    File "/usr/lib/python2.6/dist-packages/twisted/python/log.py", line 69, in callWithContext
    return context.call({ILogContext: newCtx}, func, *args, **kw)
    File "/usr/lib/python2.6/dist-packages/twisted/python/context.py", line 59, in callWithContext
    return self.currentContext().callWithContext(ctx, func, *args, **kw)
    File "/usr/lib/python2.6/dist-packages/twisted/python/context.py", line 37, in callWithContext
    return func(*args,**kw)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/selectreactor.py", line 156, in _doReadOrWrite
    self._disconnectSelectable(selectable, why, method=="doRead")
    File "/usr/lib/python2.6/dist-packages/twisted/internet/posixbase.py", line 191, in _disconnectSelectable
    selectable.readConnectionLost(f)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/tcp.py", line 508, in readConnectionLost
    self.connectionLost(reason)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/tcp.py", line 677, in connectionLost
    Connection.connectionLost(self, reason)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/tcp.py", line 519, in connectionLost
    protocol.connectionLost(reason)
    File "/usr/lib/python2.6/dist-packages/twisted/web/http.py", line 489, in connectionLost
    self.handleResponseEnd()
    File "/pentest/web/sslstrip/sslstrip/ServerConnection.py", line 119, in handleResponseEnd
    HTTPClient.handleResponseEnd(self)
    File "/usr/lib/python2.6/dist-packages/twisted/web/http.py", line 500, in handleResponseEnd
    self.handleResponse(b)
    File "/pentest/web/sslstrip/sslstrip/ServerConnection.py", line 134, in handleResponse
    self.shutdown()
    File "/pentest/web/sslstrip/sslstrip/ServerConnection.py", line 154, in shutdown
    self.client.finish()
    File "/usr/lib/python2.6/dist-packages/twisted/web/http.py", line 900, in finish
    "Request.finish called on a request after its connection was lost; "
    exceptions.RuntimeError: Request.finish called on a request after its connection was lost; use Request.notifyFinish to keep track of this.
    Traceback (most recent call last):
    File "/pentest/web/sslstrip/sslstrip.py", line 105, in main
    reactor.run()
    File "/usr/lib/python2.6/dist-packages/twisted/internet/base.py", line 1170, in run
    self.mainLoop()
    File "/usr/lib/python2.6/dist-packages/twisted/internet/base.py", line 1182, in mainLoop
    self.doIteration(t)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/selectreactor.py", line 140, in doSelect
    _logrun(selectable, _drdw, selectable, method, dict)
    --- <exception caught here> ---
    File "/usr/lib/python2.6/dist-packages/twisted/python/log.py", line 84, in callWithLogger
    return callWithContext({"system": lp}, func, *args, **kw)
    File "/usr/lib/python2.6/dist-packages/twisted/python/log.py", line 69, in callWithContext
    return context.call({ILogContext: newCtx}, func, *args, **kw)
    File "/usr/lib/python2.6/dist-packages/twisted/python/context.py", line 59, in callWithContext
    return self.currentContext().callWithContext(ctx, func, *args, **kw)
    File "/usr/lib/python2.6/dist-packages/twisted/python/context.py", line 37, in callWithContext
    return func(*args,**kw)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/selectreactor.py", line 156, in _doReadOrWrite
    self._disconnectSelectable(selectable, why, method=="doRead")
    File "/usr/lib/python2.6/dist-packages/twisted/internet/posixbase.py", line 191, in _disconnectSelectable
    selectable.readConnectionLost(f)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/tcp.py", line 508, in readConnectionLost
    self.connectionLost(reason)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/tcp.py", line 677, in connectionLost
    Connection.connectionLost(self, reason)
    File "/usr/lib/python2.6/dist-packages/twisted/internet/tcp.py", line 519, in connectionLost
    protocol.connectionLost(reason)
    File "/usr/lib/python2.6/dist-packages/twisted/web/http.py", line 489, in connectionLost
    self.handleResponseEnd()
    File "/pentest/web/sslstrip/sslstrip/ServerConnection.py", line 119, in handleResponseEnd
    HTTPClient.handleResponseEnd(self)
    File "/usr/lib/python2.6/dist-packages/twisted/web/http.py", line 500, in handleResponseEnd
    self.handleResponse(b)
    File "/pentest/web/sslstrip/sslstrip/ServerConnection.py", line 134, in handleResponse
    self.shutdown()
    File "/pentest/web/sslstrip/sslstrip/ServerConnection.py", line 154, in shutdown
    self.client.finish()
    File "/usr/lib/python2.6/dist-packages/twisted/web/http.py", line 900, in finish
    "Request.finish called on a request after its connection was lost; "
    exceptions.RuntimeError: Request.finish called on a request after its connection was lost; use Request.notifyFinish to keep track of this.
    Traceback (most recent call last):
    File "/pentest/web/sslstrip/sslstrip.py", line 105, in main
    Any1 have any ideas? The network is crashing after that.

  7. #7
    Senior Member
    Join Date
    Dec 2010
    Posts
    127

    Default Re: easy-creds 3.6 released

    I do get errors in the sslstrip window, most are benign and don't crash anything. I am not sure why your network would crash after that. What specifically do you mean by "network"?

  8. #8
    Just burned his ISO
    Join Date
    Apr 2010
    Posts
    14

    Default Re: easy-creds 3.6 released

    Well i mean that after the sslstrip error no1 can access the internet. Every1 gets timeout.
    But im not sure if its this error the cause, because either way, when i poison a network, every1 must refresh 2-3 times the webpages before they open.

    Do you have any ideas? Maybe the dhcp server is the problem?

    Thanks anyway

  9. #9
    Senior Member
    Join Date
    Dec 2010
    Posts
    127

    Default Re: easy-creds 3.6 released

    No...there is a known issue with sslstrip starting with 0.8 where sometimes you have to try to access the page more than once before it loads. I believe someone notified Moxie, but he said he could not reproduce the issue. I see it all the time. If I enter the website in the nav window and hit enter...nothing happens. If I click in the nav window and hit enter again, then it loads.

    With regards to no one being able to access the internet, I've never experienced that. I hope you're not poisoning the dhcp server.... Watch my Hack3rcon talk about properly picking targets for poisoning. You should never really do it against a server...I mean you can, but I never would.

    One quick way to DoS the LAN is to poison the physical IPs in an HSRP or CARP situation. If you poison both the virtual IP (gateway) and the physical IPs that create that gateway, the entire segment will go down.

    Happy hunting.

  10. #10
    Good friend of the forums comaX's Avatar
    Join Date
    Feb 2010
    Location
    Paris, France
    Posts
    338

    Default Re: easy-creds 3.6 released

    @comaX I submitted an "upgrade" via redmine to BT. I am not sure how long the process takes there. Should be a month or so I assume. I did give a talk at Hack3rcon, you can see it on my YouTube page I think I linked to it. Still waiting to hear back from Black Hat Abu Dhabi. Doubt they'll accept it, but I submitted for Shmoocon as well so fingers crossed.
    Thanks for the news, and I'll make sure to check the vid

    Also, even bigger news me and a few other people have officially taken over ettercap development with Alor & Naga's blessing. First new release in 6.5 years will be coming out December 2nd. All bugs fixed and currently being tested on multiple OS's. Awesome stuff!
    That is SWEET music to my ears ! Congrats bro !
    Running both KDE and GNOME BT5 flawlessly. Thank you !

Page 1 of 3 123 LastLast

Similar Threads

  1. easy-creds setup help?
    By lilsully4 in forum BackTrack 5 General Topics
    Replies: 6
    Last Post: 03-08-2013, 02:41 PM
  2. easy-creds 3.3-BT5 Released
    By ericmilam in forum BackTrack 5 Experts Section
    Replies: 55
    Last Post: 12-06-2011, 09:23 AM
  3. easy-creds setup help?
    By lilsully4 in forum BackTrack 5 Beginners Section
    Replies: 2
    Last Post: 10-31-2011, 06:46 PM
  4. easy-creds v3 released
    By ericmilam in forum Experts Forum
    Replies: 2
    Last Post: 01-08-2011, 10:28 PM
  5. easy-creds bash script
    By ericmilam in forum Experts Forum
    Replies: 6
    Last Post: 12-13-2010, 05:01 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •