Press the A key.
568 Practical Hacking Techniques and Countermeasures
A blank Filters setup screen will be displayed. Press the Enter key.
The Filter parameters screen will be displayed.
Wireless 569
Set the following parameters for the Filter:
Protocol: Tcp
Source Port: (leave blank)
(Destination) Port: 80
Search: lab81.com
Action (Drop/Replace/Log): R
Replace: www.cnn.com
Goto if match: (leave blank)
Goto if doesn??™t match: (leave blank)
Press the Enter key.
570 Practical Hacking Techniques and Countermeasures
The new Filter will now be displayed. Press the Q key.
You will be asked: Do you want to save the filters (new filter) chain?
Press the y key.
Wireless 571
The new Filter is not yet activated (notice the Filter still says OFF). Press
the S key.
Notice the Filter has now changed to ON. Press the Q key to back up one
screen.
572 Practical Hacking Techniques and Countermeasures
You will be back at the main Ettercap screen.
Now from the Linux machine every time the user attempts to go to the
Windows 2000 server (lab81.com) he or she will be brought to
http://www.cnn.com Web site.
*Note: Even though there is a newer version of Ettercap available, it tends to act somewhat
???buggy??? in the VMware environment. Another point I want to make is that
making someone go to CNN instead of the Web site he or she wanted is more
of a nuisance than anything else. The danger from this happens when the attacker
has the user redirected to a mock Web site of the original and through scripts
logs the users??™ activity, usernames, passwords, keystrokes, and so forth.
Pages:
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197