HackPi icon indicating copy to clipboard operation
HackPi copied to clipboard

Guide for only running Responder

Open derrabe opened this issue 8 years ago • 1 comments

Hi, I was wondering what needs to be disabled/commented out to just run Responder to capture the creds (i.e. not run PoisonTap) ?

Is it a matter of just commenting out the following lines in rc.local?

/sbin/sysctl -w net.ipv4.ip_forward=1 /sbin/iptables -t nat -A PREROUTING -i br0 -p tcp --dport 80 -j REDIRECT --to-port 1337
/usr/bin/screen -dmS dnsspoof /usr/sbin/dnsspoof -i br0 port 53 /usr/bin/screen -dmS node /usr/bin/nodejs /home/pi/poisontap/pi_poisontap.js

Thanks for the great work!

derrabe avatar May 23 '17 03:05 derrabe

Hi,

To disable PoisonTap and leave only Responder, set rc.local as follows:

# Start the DHCP server
#/sbin/route add -net 0.0.0.0/0 br0
/etc/init.d/isc-dhcp-server start
# Set some other paramaters
/sbin/sysctl -w net.ipv4.ip_forward=1
#/sbin/iptables -t nat -A PREROUTING -i br0 -p tcp --dport 80 -j REDIRECT --to-port 1337
# Start some servers
#/usr/bin/screen -dmS dnsspoof /usr/sbin/dnsspoof -i br0 port 53
#/usr/bin/screen -dmS node /usr/bin/nodejs /home/pi/poisontap/pi_poisontap.js

But please not that I haven't tested it yet. Let me know how this goes!

wismna avatar May 23 '17 13:05 wismna