Results 1 to 2 of 2

Thread: Ettercap ARP not Poisoning ??

  1. #1
    Just burned his ISO
    Join Date
    Jan 2011

    Default Ettercap ARP not Poisoning ??


    If i start ettercap it will not poison..

    This is what i done:

    i changed in the config file:
    # if you use iptables:
    redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"
    redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"

    Sniff -> Unified Sniffing

    Eth0 -> OK ………………………..(This runs Sniffing on your first Ethernet card)

    Hosts -> Scan for hosts ………… (Scans the network for targets)

    Hosts -> Hosts List ………………….(Opens your hosts list

    default gateway to target 1
    Attacking computers to target 2

    Mitm -> ARP poisoning -> Select “Sniff remote connections” OK

    Start -> Start Sniffing

    An this is the result:

    Listening on eth0... (Ethernet)

    eth0 -> 00:0C:29:A3:71:E2

    Privileges dropped to UID 0 GID 0...

    28 plugins
    39 protocol dissectors
    53 ports monitored
    7587 mac vendor fingerprint
    1698 tcp OS fingerprint
    2183 known services
    Randomizing 255 hosts for scanning...
    Scanning the whole netmask for 255 hosts...
    4 hosts added to the hosts list...
    Host added to TARGET1
    Host added to TARGET2
    Host added to TARGET2
    Host added to TARGET2

    ARP poisoning victims:

    GROUP 1 : 00:0B:6B:4E:B9:FA

    GROUP 2 : 00:60:B3:5D:5E:0B
    GROUP 2 : 00:0B:6B:87:4F:92
    GROUP 2 : 00:0C:42:14:8D:86
    Starting Unified sniffing...

    DHCP: [] ACK : GW DNS
    DHCP: [] ACK : GW DNS
    DHCP: [] ACK : GW DNS
    DHCP: [] ACK : GW DNS
    DHCP: [] ACK : GW DNS
    DHCP: [] ACK : GW DNS
    Activating chk_poison plugin...
    chk_poison: Checking poisoning status...
    chk_poison: No poisoning between ->
    chk_poison: No poisoning between ->
    chk_poison: No poisoning between ->
    chk_poison: No poisoning between ->
    chk_poison: No poisoning between ->

    Hope somebody can help me!!!
    Thank you

  2. #2
    Join Date
    Feb 2010

    Default Re: Ettercap ARP not Poisoning ??

    I have found the chk_poison module to be unreliable at best. Have you actually checked any of the victim machines to see if they have indeed been poisoned? It also may help to know what you are trying to accomplish. For instance, unless you are attempting a MITM attack you don't need to turn on IP forwarding. Also, until you have narrowed down the problem I would suggest attacking just one machine at a time. Also also, to say there is a wealth of videos online about this subject would be quite the understatement. The only other subject I can think of that has more tutorials and how-to's would WEP cracking. Google, as per usual, is ever useful.

Similar Threads

  1. Ettercap With ARP Poisoning
    By micole in forum BackTrack Howtos
    Replies: 24
    Last Post: 04-23-2011, 12:33 PM
  2. ettercap not poisoning
    By rogue030 in forum OLD Wireless
    Replies: 3
    Last Post: 01-10-2010, 07:24 PM
  3. ettercap-ng and arp poisoning
    By Nlantz in forum OLD Newbie Area
    Replies: 6
    Last Post: 09-30-2009, 04:30 PM
  4. Ettercap ARP poisoning not working with XP SP3?
    By Homer4Life in forum OLD BT4beta Software Related Issues
    Replies: 7
    Last Post: 06-02-2009, 02:16 AM
  5. Poisoning problem in ettercap
    By Phonatacid in forum OLD Newbie Area
    Replies: 1
    Last Post: 12-31-2008, 03:16 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts