Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now that we know how ARP spoofing works. 2
2
Let's see how we can run this attack 3
3
and redirect the flow of data 4
4
so it flows through our device. 5
5
This will allows us to intercept data 6
6
and see everything sent to and from a target computer 7
7
including, usernames, passwords and so on. 8
8
Now there are a number of tools that can be used 9
9
to run an ARP spoofing attack, 10
10
you can even build your own tool 11
11
and I covered this in my Python programing course. 12
12
But in this lecture I wanna show you 13
13
how to use a very simple yet reliable tool called arpspoof, 14
14
then in the next lectures we'll use 15
15
a tool called BetterCAP because it has more features. 16
16
Basically, the main reason why I want to cover arpspoof 17
17
in this lecture, because it is a very simple tool 18
18
but it's very reliable. 19
19
It's also ported to many operating systems, 20
20
including iOS and Android. 21
21
Therefore if you learn how to use it here 22
22
you'll be able to use this tool 23
23
on all of the other operating systems. 24
24
So you can only use this tool to redirect the flow of data 25
25
and make it flow through your computer, 26
26
and then you'll have to use another tool 27
27
like a packet sniffer like Wireshark to analyze this data 28
28
and do more stuff with it, 29
29
and we'll cover all of this later on in the course. 30
30
Now, using arpspoof is very simple. 31
31
First, we're gonna have to type its name. 32
32
So it's arpspoof then we're gonna do dash I, 33
33
to specify the interface that is connected 34
34
to the target network and in my case it is eth0, 35
35
because that's the interface that's connected 36
36
to the network. 37
37
So if I do, ifconfig, 38
38
you'll see eth0 is the interface that's connected. 39
39
Now as you can see I'm gonna be running this attack 40
40
against my virtual not network. 41
41
You can run this attack against any type of network, 42
42
even Wi-Fi networks and I will cover that 43
43
later on in the course. 44
44
But for now just until you properly understand 45
45
how this works, I highly recommend you 46
46
do like I'm doing right now 47
47
and test the attack against the virtual node network. 48
48
So all you'll have to do is make sure the Kali machine 49
49
and the target windows machine are both configured 50
50
to use the same node network. 51
51
So, we're gonna do dash t to specify the target 52
52
and my target is at 10.0.2.7. 53
53
As you can see in here that is the IP of my target. 54
54
And I'm gonna have to give it the IP of the gateway 55
55
which is 10.0.2.1 56
56
as you can see in here. 57
57
Now this will spoof the target, 58
58
telling him that I am the router. 59
59
We'll also need to run this command once more in here. 60
60
So, I'm gonna clear the screen and again I'm gonna do 61
61
arpspoof -i eth0 62
62
and the target this time is going to be 10.0.2.1 63
63
and 10.0.2.7. 64
64
So right now we're gonna be telling the router 65
65
that I am the victim, 66
66
so the first one will fool the victim, 67
67
the second will fool the router. 68
68
Now keep in mind this attack will work against both internet 69
69
and Wi-Fi or wireless networks. 70
70
I'm running it right now against the virtual networks 71
71
which acts as an internet or a wired network, 72
72
but the attack can be executed exactly the same 73
73
against wireless networks. 74
74
All you have to do is connect a wireless adapter 75
75
to the Kali machine, 76
76
connect the adapter to the target network and use it. 77
77
So the same concept as the networks kinda applies. 78
78
You need to have a wireless adapter 79
79
that works well with Kali 80
80
and you need to have that adapter connected to Kali 81
81
and connected to the target network. 82
82
So, I'm gonna hit enter here 83
83
and I'm gonna hit enter here, 84
84
and now if we go to the target machine 85
85
and run the same command arp -a, 86
86
you're gonna see that the MAC address now 87
87
for the router is different than what it was, 88
88
and this is the MAC address of the Kali machine. 89
89
So right now, this window's machine 90
90
thinks the router is at this MAC address 91
91
and every time it needs to send a request 92
92
it will send it to this MAC address, 93
93
which means that they will be sent 94
94
to this computer right here. 95
95
Now, this computer is not a router so when it gets requests, 96
96
it's actually going to stop them from flowing 97
97
and going to the router. 98
98
This is a security feature in Linux. 99
99
So, you need to enable port forwarding so that 100
100
this computer would allow packets to flow through it 101
101
just like a router. 102
102
Now to enable port forwarding, 103
103
we're gonna do echo one to proc/sys/net/ipv4/ip_forward, 104
104
and as you can see this command 105
105
gets executed with no issues. 106
106
And right now this computer 107
107
will still have its internet access, 108
108
so we can go and browse any website we want, 109
109
but all these requests are not going directly to the router, 110
110
but they are going to this computer first 111
111
and then this computer is forwarding them to the router, 112
112
as shown in this diagram, and then when the response's 113
113
come back they are gonna go to the hacker first, 114
114
and then they go to the victim. 115
115
So as you can see a very simple tool, 116
116
it allows us to redirect the flow of data 117
117
so it flows through our computer 118
118
allowing us to become the man in the middle, 119
119
and once we're the man in the middle, 120
120
we can inject code in the browser of the target. 121
121
We can steal usernames, passwords, 122
122
see all the information that the person sends and receives, 123
123
replace downloaded files with Trojans and much much more.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.