Sniffing & spoofing
Ninguna herramienta coincide.
-
aboveweb
Passive network sniffer aimed at spotting misconfigurations and cleartext protocol weaknesses on networks you may watch.
-
bettercapweb
Network attack framework for MITM, sniffing, and spoofing on networks you are allowed to touch.
-
darkstatweb
Lightweight traffic analyzer that graphs who talks to whom on a span or lab interface.
-
dnschefweb
DNS proxy that lies on purpose so you can redirect lab clients during phishing or MITM drills.
ayuda
/usr/bin/dnschef:453: SyntaxWarning: "\/" is an invalid escape sequence. Such sequences will not work in the future. Did you mean "\\/"? A raw string is also an option. header += " / _` | '_ \/ __|/ __| '_ \ / _ \ _|\n" /usr/bin/dnschef:454: SyntaxWarning: "\_" is an invalid escape sequence. Such sequences will not work in the future. Did you mean "\\_"? A raw string is also an option. header += " | (_| | | | \__ \ (__| | | | __/ | \n" /usr/bin/dnschef:455: SyntaxWarning: "\_" is an invalid escape sequence. Such sequences will not work in the future. Did you mean "\\_"? A raw string is also an option. header += " \__,_|_| |_|___/\___|_| |_|\___|_| \n" usage: dnschef [options]: _ _ __ | | version 0.4 | | / _| __| |_ __ ___ ___| |__ ___| |_ / _` | '_ \/ __|/ __| '_ \ / _ \ _| | (_| | | | \__ \ (__| | | | __/ | \__,_|_| |_|___/\___|_| |_|\___|_| iphelix@thesprawl.org DNSChef is a highly configurable DNS Proxy for Penetration Testers and Malware Analysts. It is capable of fine configuration of which DNS replies to modify or to simply proxy with real responses. In order to take advantage of the tool you must either manually configure or poison DNS server entry to point to DNSChef. The tool requires root privileges to run on privileged ports. options: -h, --help show this help message and exit --fakedomains thesprawl.org,google.com A comma separated list of domain names which will be resolved to FAKE values specified in the the above parameters. All other domain names will be resolved to their true values. --truedomains thesprawl.org,google.com A comma separated list of domain names which will be resolved to their TRUE values. All other domain names will be resolved to fake values specified in the above parameters. Fake DNS records:: --fakeip 192.0.2.1 IP address to use for matching DNS queries. If you use this parameter without specifying domain names, then all 'A' queries will be spoofed. Consider using --file argument if you need to define more than one IP address. --fakeipv6 2001:db8::1 IPv6 address to use for matching DNS queries. If you use this parameter without specifying domain names, then all 'AAAA' queries will be spoofed. Consider using --file argument if you need to define more than … (46 more lines — see the tool's home page) -
driftnetweb
Shows images seen in cleartext network traffic on a span port you may monitor.
-
Classic suite for capturing cleartext passwords and URLs on networks you are allowed to sniff.
ayuda
arpspoof: libnet_open_link(): UID/EUID 0 or capability CAP_NET_RAW required -
GUI front end for ettercap MITM demos on LANs you own.
ayuda
ettercap 0.8.4.1 copyright 2001-2026 Ettercap Development Team Usage: ettercap [OPTIONS] [TARGET1] [TARGET2] TARGET is in the format MAC/IP/IPv6/PORTs (see the man for further detail) Sniffing and Attack options: -M, --mitm <METHOD:ARGS> perform a mitm attack -o, --only-mitm don't sniff, only perform the mitm attack -b, --broadcast sniff packets destined to broadcast -B, --bridge <IFACE> use bridged sniff (needs 2 ifaces) -p, --nopromisc do not put the iface in promisc mode -S, --nosslmitm do not forge SSL certificates -u, --unoffensive do not forward packets -r, --read <file> read data from pcapfile <file> -f, --pcapfilter <string> set the pcap filter <string> -R, --reversed use reversed TARGET matching -t, --proto <proto> sniff only this proto (default is all) --certificate <file> certificate file to use for SSL MiTM --private-key <file> private key file to use for SSL MiTM User Interface Type: -T, --text use text only GUI -q, --quiet do not display packet contents -s, --script <CMD> issue these commands to the GUI -C, --curses use curses GUI -D, --daemon daemonize ettercap (no GUI) -G, --gtk use GTK+ GUI Logging options: -w, --write <file> write sniffed data to pcapfile <file> -L, --log <logfile> log all the traffic to this <logfile> -l, --log-info <logfile> log only passive infos to this <logfile> -m, --log-msg <logfile> log all the messages to this <logfile> -c, --compress use gzip compression on log files Visualization options: -d, --dns resolves ip addresses into hostnames -V, --visual <format> set the visualization format -e, --regex <regex> visualize only packets matching this regex -E, --ext-headers print extended header for every pck -Q, --superquiet do not display user and password LUA options: --lua-script <script1>,[<script2>,...] comma-separted list of LUA scripts … (21 more lines — see the tool's home page) -
ettercap-text-onlyweb
Text-mode ettercap for scripted ARP spoofing labs without a desktop.
-
fikedweb
Fake IKE daemon used to study VPN handshake behaviour in a lab.
-
hexinjectweb
Packet injector and sniffer with a hex-friendly workflow for crafting frames on a lab NIC.
-
isr-evilgradeweb
Evilgrade framework for serving trojaned updates when you control the fake update path in a lab.
-
macchangerweb
Temporarily changes an interface MAC address for lab network identity tests.
ayuda
GNU MAC Changer Usage: macchanger [options] device -h, --help Print this help -V, --version Print version and exit -s, --show Print the MAC address and exit -e, --ending Don't change the vendor bytes -a, --another Set random vendor MAC of the same kind -A Set random vendor MAC of any kind -p, --permanent Reset to original, permanent hardware MAC -r, --random Set fully random MAC -l, --list[=keyword] Print known vendors -b, --bia Pretend to be a burned-in-address -m, --mac=XX:XX:XX:XX:XX:XX --mac XX:XX:XX:XX:XX:XX Set the MAC XX:XX:XX:XX:XX:XX Report bugs to https://github.com/alobbs/macchanger/issues -
High-performance Linux packet sniffing toolkit for capture and analysis on busy links.
ayuda
astraceroute 0.6.9, autonomous system trace route utility http://www.netsniff-ng.org Usage: astraceroute [options] Options: -H|--host <host> Host/IPv4/IPv6 to lookup AS route to -p|--port <port> Hosts port to lookup AS route to -i|-d|--dev <device> Networking device, e.g. eth0 -b|--bind <IP> IP address to bind to, Must specify -6 for an IPv6 address -f|--init-ttl <ttl> Set initial TTL -m|--max-ttl <ttl> Set maximum TTL (def: 30) -q|--num-probes <num> Number of max probes for each hop (def: 2) -x|--timeout <sec> Probe response timeout in sec (def: 3) -X|--payload <string> Specify a payload string to test DPIs -l|--totlen <len> Specify total packet len -4|--ipv4 Use IPv4-only requests -6|--ipv6 Use IPv6-only requests -n|--numeric Do not do reverse DNS lookup for hops -u|--update Update GeoIP databases -L|--latitude Show latitude and longitude -N|--dns Do a reverse DNS lookup for hops -S|--syn Set TCP SYN flag -A|--ack Set TCP ACK flag -F|--fin Set TCP FIN flag -P|--psh Set TCP PSH flag -U|--urg Set TCP URG flag -R|--rst Set TCP RST flag -E|--ecn-syn Send ECN SYN packets (RFC3168) -t|--tos <tos> Set the IP TOS field -G|--nofrag Set do not fragment bit -Z|--show-packet Show returned packet on each hop -v|--version Print version and exit -h|--help Print this help and exit Examples: IPv4 trace of AS with TCP SYN probe (this will most-likely pass): astraceroute -i eth0 -N -S -H netsniff-ng.org IPv4 trace of AS with TCP ECN SYN probe: astraceroute -i eth0 -N -E -H netsniff-ng.org IPv4 trace of AS with TCP FIN probe: astraceroute -i eth0 -N -F -H netsniff-ng.org IPv4 trace of AS with Xmas probe: astraceroute -i eth0 -N -FPU -H netsniff-ng.org IPv4 trace of AS with Null probe with ASCII payload: astraceroute -i eth0 -N -H netsniff-ng.org -X "censor-me" -Z … (15 more lines — see the tool's home page) -
rebinddns-rebind
DNS rebinding helper for demonstrating how browser same-origin assumptions can be tricked.
ayuda
Rebind v0.3.4 Usage: dns-rebind [OPTIONS] -i <interface> Specify the network interface to bind to -d <fqdn> Specify your registered domain name -u <user> Specify the Basic Authentication user name [admin] -a <pass> Specify the Basic Authentication password [admin] -r <path> Specify the initial URL request path [/] -t <ip> Specify a comma separated list of target IP addresses [client IP] -n <time> Specify the callback interval in milliseconds [2000] -p <port> Specify the target port [80] -c <port> Specify the callback port [81] -C <value> Specify a cookie to set for the client -H <file> Specify a file of HTTP headers for the client to send to the target -
sniffjokeweb
Scrambles cleartext TCP in transit to frustrate naive sniffers during authorized network tests.
-
tcpflowweb
Reassembles TCP streams into files, one flow per side, for protocol and payload review.
-
Replays pcap traffic at chosen speeds so IDS, mirrors, or labs see the same packets again.
ayuda
tcpbridge (tcpbridge) - Bridge network traffic across two interfaces Usage: tcpbridge [ -<flag> [<val>] | --<name>[{=| }<val>] ]... : -r, --portmap=str Rewrite TCP/UDP ports - may appear up to 9999 times -s, --seed=num Randomize src/dst IPv4/v6 addresses w/ given seed - prohibits the option 'fuzz-seed' -N, --pnat=str Rewrite IPv4/v6 addresses using pseudo-NAT - prohibits the option 'srcipmap' - may appear up to 2 times -S, --srcipmap=str Rewrite source IPv4/v6 addresses using pseudo-NAT - prohibits the option 'pnat' -D, --dstipmap=str Rewrite destination IPv4/v6 addresses using pseudo-NAT - prohibits the option 'pnat' --tcp-sequence=num Change TCP Sequence (and ACK) numbers /w given seed - it must be in the range: greater than or equal to 1 -b, --skipbroadcast Skip rewriting broadcast/multicast IPv4/v6 addresses -C, --fixcsum Force recalculation of IPv4/TCP/UDP header checksums --fixhdrlen Alter IP/TCP header len to match packet length -m, --mtu=num Override default MTU length (1500 bytes) - it must be in the range: 1 to 262144 --mtu-trunc Truncate packets larger then specified MTU -E, --efcs Remove Ethernet checksums (FCS) from end of frames --ttl=str Modify the IPv4/v6 TTL/Hop Limit --tos=num Set the IPv4 TOS/DiffServ/ECN byte - it must be in the range: 0 to 255 --tclass=num Set the IPv6 Traffic Class byte - it must be in the range: 0 to 255 --flowlabel=num Set the IPv6 Flow Label - it must be in the range: 0 to 1048575 -F, --fixlen=str Pad or truncate packet data to match header length --fuzz-seed=num Fuzz 1 in X packets. Edit bytes, length, or emulate packet drop - it must be in the range: greater than or equal to 0 --fuzz-factor=num Set the Fuzz 1 in X packet ratio (default 1 in 8 packets) - requires the option 'fuzz-seed' - it must be in the range: greater than or equal to 1 … (84 more lines — see the tool's home page) -
wifi-honeyweb
Spins up lookalike SSIDs so you can watch which clients prefer which names in a controlled wireless honey setup.
Cuando hay un propósito escrito para esta ruta, se muestra primero. Si no, ves el resumen del paquete. La ayuda se captura en vivo desde un Kali cuando está disponible.