OSiUX · @osiux
153 followers · 143 posts · Server rebel.ar

I'm going to summarize.
This really good write up on how to use simple, readily available tools to perform good security research. And it is written in such a way that even a beginner could follow it.
They used , specifically , , and an arpspoof script (there are tools in Kali that can do this for you like or , but they probably did not need something that full featured).
They debugged the protocol to figure out where the PSI values were stored and then built a MiTM script, also in python, that could manipulate embedded data in either direction or both directions.
Simplest fix is "encrypt your protocol".

#kalilinux #wireshark #scapy #python #dsniff #ettercap

Last updated 2 years ago