rooshvforum.network is a fully functional forum: you can search, register, post new threads etc...
Old accounts are inaccessible: register a new one, or recover it when possible. x


Essential android tools for modern players and alphas
#26

Essential android tools for modern players and alphas

Quote: (09-28-2013 09:18 AM)mental Wrote:  

Ok, I've been testing these apps, and it looks like password sniffing from both FaceNiff and dSploit doesn't work if the victim has a smartphone (it still sniffs if the page is http instead of https), but if the victim has a PC, it works every time. The only way I've been able to obtain Facebook logins is by using session sniffing in dSploit, and sometimes it doesn't work. Other attacks still work - redirect, replace text, script injection etc. Also, I've discovered that by installing SSLStrip, running password sniffer in dSploit on subnet, then activating both ARP Spoof and SSLStrip in the SSLStrip app while dSploit is in background (by pressing home button), it logs every password on PC, including eBay, PayPal... Only google account seem to be secure from this - I couldn't sniff either gmail or youtube.

Worth noting that I'm on android 4.3 and I cannot get dSploit to work. It just force closes one me whenever I select a router.

Edit: Nevermind, it seems that when over around 20 devices connect to a single router it force closes if you try to select the router itself rather than devices individually.
Reply
#27

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:06 PM)Slacker101 Wrote:  

Quote: (09-28-2013 09:18 AM)mental Wrote:  

Ok, I've been testing these apps, and it looks like password sniffing from both FaceNiff and dSploit doesn't work if the victim has a smartphone (it still sniffs if the page is http instead of https), but if the victim has a PC, it works every time. The only way I've been able to obtain Facebook logins is by using session sniffing in dSploit, and sometimes it doesn't work. Other attacks still work - redirect, replace text, script injection etc. Also, I've discovered that by installing SSLStrip, running password sniffer in dSploit on subnet, then activating both ARP Spoof and SSLStrip in the SSLStrip app while dSploit is in background (by pressing home button), it logs every password on PC, including eBay, PayPal... Only google account seem to be secure from this - I couldn't sniff either gmail or youtube.
[Image: n3wbcJQ.png]

Worth noting that I'm on android 4.3 and I cannot get dSploit to work. It just force closes one me whenever I select a router.

Try installing one of these APK's. If it still doesn't work wait for a couple of days - the author said there will be a new version coming out soon.

Edit: I've seen you've solved it. I remember something about an issue with Superuser, and that SuperSu works much better for dSploit, so if you have Superuser, uninstall it and install SuperSu instead.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#28

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:13 PM)mental Wrote:  

Quote: (09-30-2013 02:06 PM)Slacker101 Wrote:  

Quote: (09-28-2013 09:18 AM)mental Wrote:  

Ok, I've been testing these apps, and it looks like password sniffing from both FaceNiff and dSploit doesn't work if the victim has a smartphone (it still sniffs if the page is http instead of https), but if the victim has a PC, it works every time. The only way I've been able to obtain Facebook logins is by using session sniffing in dSploit, and sometimes it doesn't work. Other attacks still work - redirect, replace text, script injection etc. Also, I've discovered that by installing SSLStrip, running password sniffer in dSploit on subnet, then activating both ARP Spoof and SSLStrip in the SSLStrip app while dSploit is in background (by pressing home button), it logs every password on PC, including eBay, PayPal... Only google account seem to be secure from this - I couldn't sniff either gmail or youtube.

Worth noting that I'm on android 4.3 and I cannot get dSploit to work. It just force closes one me whenever I select a router.

Try installing one of these APK's. If it still doesn't work wait for a couple of days - the author said there will be a new version coming out soon.

When you had success with the password sniffer and then SSLStrip you said you were using it on your own subnet rather than the router itself?
Reply
#29

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:14 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:13 PM)mental Wrote:  

Quote: (09-30-2013 02:06 PM)Slacker101 Wrote:  

Quote: (09-28-2013 09:18 AM)mental Wrote:  

Ok, I've been testing these apps, and it looks like password sniffing from both FaceNiff and dSploit doesn't work if the victim has a smartphone (it still sniffs if the page is http instead of https), but if the victim has a PC, it works every time. The only way I've been able to obtain Facebook logins is by using session sniffing in dSploit, and sometimes it doesn't work. Other attacks still work - redirect, replace text, script injection etc. Also, I've discovered that by installing SSLStrip, running password sniffer in dSploit on subnet, then activating both ARP Spoof and SSLStrip in the SSLStrip app while dSploit is in background (by pressing home button), it logs every password on PC, including eBay, PayPal... Only google account seem to be secure from this - I couldn't sniff either gmail or youtube.

Worth noting that I'm on android 4.3 and I cannot get dSploit to work. It just force closes one me whenever I select a router.

Try installing one of these APK's. If it still doesn't work wait for a couple of days - the author said there will be a new version coming out soon.

When you had success with the password sniffer and then SSLStrip you said you were using it on your own subnet rather than the router itself?

Yes, password sniffing doesn't work on router.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#30

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:16 PM)mental Wrote:  

Quote: (09-30-2013 02:14 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:13 PM)mental Wrote:  

Quote: (09-30-2013 02:06 PM)Slacker101 Wrote:  

Quote: (09-28-2013 09:18 AM)mental Wrote:  

Ok, I've been testing these apps, and it looks like password sniffing from both FaceNiff and dSploit doesn't work if the victim has a smartphone (it still sniffs if the page is http instead of https), but if the victim has a PC, it works every time. The only way I've been able to obtain Facebook logins is by using session sniffing in dSploit, and sometimes it doesn't work. Other attacks still work - redirect, replace text, script injection etc. Also, I've discovered that by installing SSLStrip, running password sniffer in dSploit on subnet, then activating both ARP Spoof and SSLStrip in the SSLStrip app while dSploit is in background (by pressing home button), it logs every password on PC, including eBay, PayPal... Only google account seem to be secure from this - I couldn't sniff either gmail or youtube.

Worth noting that I'm on android 4.3 and I cannot get dSploit to work. It just force closes one me whenever I select a router.

Try installing one of these APK's. If it still doesn't work wait for a couple of days - the author said there will be a new version coming out soon.

When you had success with the password sniffer and then SSLStrip you said you were using it on your own subnet rather than the router itself?

Yes, password sniffing doesn't work on router.
Hmm okay and that sniffs for everyone connected when you do it through the subnet or you have to do everyone individually?

Also my last thought is whenever I try any of the redirects or replacement text/video/image tools I get the error "unable to create the proxy, please check your connection and port availability." Any ideas?
Reply
#31

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:26 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:16 PM)mental Wrote:  

Quote: (09-30-2013 02:14 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:13 PM)mental Wrote:  

Quote: (09-30-2013 02:06 PM)Slacker101 Wrote:  

Worth noting that I'm on android 4.3 and I cannot get dSploit to work. It just force closes one me whenever I select a router.

Try installing one of these APK's. If it still doesn't work wait for a couple of days - the author said there will be a new version coming out soon.

When you had success with the password sniffer and then SSLStrip you said you were using it on your own subnet rather than the router itself?

Yes, password sniffing doesn't work on router.
Hmm okay and that sniffs for everyone connected when you do it through the subnet or you have to do everyone individually?

Also my last thought is whenever I try any of the redirects or replacement text/video/image tools I get the error "unable to create the proxy, please check your connection and port availability." Any ideas?

Subnet and router is for devices.
About that error, I've only got it if the device was disconnected, try individual devices - maybe someone disconnected while you were spoofing on subnet, altough I didn't get it on subnet.
Edit: I've tried disabling network adapter while I was spoofing on subnet and I didn't get an error, maybe you should try reconnecting to wifi or relaunch dSploit...

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#32

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:28 PM)mental Wrote:  

Quote: (09-30-2013 02:26 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:16 PM)mental Wrote:  

Quote: (09-30-2013 02:14 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:13 PM)mental Wrote:  

Try installing one of these APK's. If it still doesn't work wait for a couple of days - the author said there will be a new version coming out soon.

When you had success with the password sniffer and then SSLStrip you said you were using it on your own subnet rather than the router itself?

Yes, password sniffing doesn't work on router.
Hmm okay and that sniffs for everyone connected when you do it through the subnet or you have to do everyone individually?

Also my last thought is whenever I try any of the redirects or replacement text/video/image tools I get the error "unable to create the proxy, please check your connection and port availability." Any ideas?

Subnet and router is for devices.
About that error, I've only got it if the device was disconnected, try individual devices - maybe someone disconnected while you were spoofing on subnet, altough I didn't get it on subnet.
Edit: I've tried disabling network adapter while I was spoofing on subnet and I didn't get an error, maybe you should try reconnecting to wifi or relaunch dSploit...

I got the error to go away by rebooting the phone. I'm currently having no luck with the password sniffer. I tried the other tools and the video spoofer just broke all videos, not redirecting them. The text spoofer and redirect did not seem to work at all.
Reply
#33

Essential android tools for modern players and alphas

Quote: (09-30-2013 02:57 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:28 PM)mental Wrote:  

Quote: (09-30-2013 02:26 PM)Slacker101 Wrote:  

Quote: (09-30-2013 02:16 PM)mental Wrote:  

Quote: (09-30-2013 02:14 PM)Slacker101 Wrote:  

When you had success with the password sniffer and then SSLStrip you said you were using it on your own subnet rather than the router itself?

Yes, password sniffing doesn't work on router.
Hmm okay and that sniffs for everyone connected when you do it through the subnet or you have to do everyone individually?

Also my last thought is whenever I try any of the redirects or replacement text/video/image tools I get the error "unable to create the proxy, please check your connection and port availability." Any ideas?

Subnet and router is for devices.
About that error, I've only got it if the device was disconnected, try individual devices - maybe someone disconnected while you were spoofing on subnet, altough I didn't get it on subnet.
Edit: I've tried disabling network adapter while I was spoofing on subnet and I didn't get an error, maybe you should try reconnecting to wifi or relaunch dSploit...

I got the error to go away by rebooting the phone. I'm currently having no luck with the password sniffer. I tried the other tools and the video spoofer just broke all videos, not redirecting them. The text spoofer and redirect did not seem to work at all.

Make sure not to use any other app while those two are running because the phone might close one of them. Maybe there were too much devices connected so try on just one computer and see if they work then because there's sometimes problems with them.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#34

Essential android tools for modern players and alphas

No luck. Tried everything on my IPad's IP and no matter what I choose nothing had an effect on it.
Reply
#35

Essential android tools for modern players and alphas

Quote: (09-30-2013 03:46 PM)Slacker101 Wrote:  

No luck. Tried everything on my IPad's IP and no matter what I choose nothing had an effect on it.

Dunno then, try searching this xda thread.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#36

Essential android tools for modern players and alphas

It's probably the ROM/kernel I'm currently using. The kernel I'm using seems like it is causing the WiFi to act odd. I'll try a different ROM/kernel tomorrow and report back. Plus I'll downgrade to 4.2. Alternatively it could be that the modem I'm trying to do it on has some sort of countermeasure. It's a college's guest network that's insecure.
Reply
#37

Essential android tools for modern players and alphas

Quote: (09-30-2013 03:54 PM)Slacker101 Wrote:  

It's probably the ROM I'm currently using. The kernal I'm using seems like it is causing the WiFi to act odd. I'll try a different ROM/kernal tomorrow and report back. Plus I'll downgrade to 4.2. Alternatively it could be that the modem I'm trying to do it on has some sort of countermeasure. It's a college's guest network that's insecure.

Try disabling firewall in router config page (dSploit shows the router ip, just type it in URL bar, the username and pass are usually both admin or username admin and no pass). I haven't yet encountered a router whose firewall stops this.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#38

Essential android tools for modern players and alphas

It's the university's so they changed the user name and passwords. It is supposedly firewall-less with no security. I believe them though so it must be something on my end.
Reply
#39

Essential android tools for modern players and alphas

Quote: (09-30-2013 04:09 PM)Slacker101 Wrote:  

It's the university's so they changed the user name and passwords. It is supposedly firewall-less with no security. I believe them though so it must be something on my end.

Okay, I had to reinstall 4.2.2 leaked on my S3, and no MITM attack worked. I got into CWM recovery, selected fix permission and cleared dalvik cache, and they started working, and also I've turned off the router for about 10 minutes, and it works again. Try clearing the dalvik cache and fixing permissions, maybe it will work, but by clearing permission you'll have to rerun all root apps and set them again to your preferences

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#40

Essential android tools for modern players and alphas

Ok, found another combo - Faceniff+dSploit: same as dSploit-SSLStrip, first run dSploit pass sniffer then select SSLStrip in Faceniff. This one has the advantage of Faceniff saving session and dSploit automatically saving passwords in a log, it's less demanding on CPU and SSLStrip can break the facebook login page. Of course, if you want all the pages, not only those Faceniff supports, and of course, I don't know if this will work on smartphones. I'll try to borrow a friend's phone and report. If Faceniff gives an error about bind address (which it did on my phone and that's why I've discovered it only now) make sure you not run any MITM atrack except password sniffer, and if it still persists restart dsploit and faceniff or restart your phone or try going to recovery (turn off your phone and hold a certain combination, it's usually volume up+home button+power up, or just volume up+power button, search google if these combos don't work) and clearing dalvik cache (don't worry, it won't delete anything, it just forces the phone to load all app info over again).

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#41

Essential android tools for modern players and alphas

Quote: (10-01-2013 07:37 AM)mental Wrote:  

Of course, if you want all the pages, not only those Faceniff supports, and of course, I don't know if this will work on smartphones.

I forgot to write you'll have to run SSLStrip if you want every https page instead of those Faceniff supports, and SSLStrip works on phones.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#42

Essential android tools for modern players and alphas

I tried clearing cache and dalvik cache as well as fixing permissions. I still can't get it to work.
Reply
#43

Essential android tools for modern players and alphas

Quote: (10-01-2013 02:28 PM)Slacker101 Wrote:  

I tried clearing cache and dalvik cache as well as fixing permissions. I still can't get it to work.

Make sure you run SuperSu again after clearing cache. If that doesn't work maybe because your system is 4.3... I don't know any other reason it's not working. Either wait for new version or install 4.2 or 4.1.x, or try reinstalling Busybox as normal and smart just to make sure.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#44

Essential android tools for modern players and alphas

How do I install Framaroot?
Reply
#45

Essential android tools for modern players and alphas

Do you know how to monitor whatsapp chats?
Reply
#46

Essential android tools for modern players and alphas

Quote: (10-02-2013 03:51 AM)Every10GivesMeA10 Wrote:  

Do you know how to monitor whatsapp chats?

It's a little bit complicated, you need to capture packets with something like tPacketCapture then analyze them on your PC with something like Wireshark, but that could take a while... tPacketCapture Pro (search google... you know why) can filter by protocol or app, but I haven't tried, so I couldn't take you through it.

Quote: (10-02-2013 12:13 AM)JackDavey Wrote:  

How do I install Framaroot?

You kidding me or what? Just transfer or download it to your phone, make sure Unknown sources in Settings->Security (or Settings->Applications->Security on some older phones) is ticked, then navigate to the download location using a file manager such as ES File Explorer. Don't forget to select it when you've navigated to the download folder and press Install.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#47

Essential android tools for modern players and alphas

Edit: double post...

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#48

Essential android tools for modern players and alphas

Is there a pc version of these tools?

Especially the Facebook one?

valhalla
Reply
#49

Essential android tools for modern players and alphas

Quote: (10-02-2013 06:12 AM)Valhalla Wrote:  

Is there a pc version of these tools?

Especially the Facebook one?

Cain and abel, interceptor-ng, ettercap... Just search arp spoofing. You can also download backtrack linux or kali linux - these are made specifically for pentesting. They aren't as user friendly as these for android so it's gonna take some effort to learn them.

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply
#50

Essential android tools for modern players and alphas

Ok, I can confirm that dSploit-Faceniff DOES work on phones if they're using a browser. I just don't know if it works if they're using the official facebook app... Now you have a reason to keep your wifi open [Image: evil.gif]

Check out my thread Essential android tools for modern players and alphas to find out how to make your android phone your wingman, or click here and scroll down if you only need to root it.


Want sound that puts iPods and iPhones to shame? I got you covered!
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)