Author Topic: intercepter-ios  (Read 3341 times)

alizanda

  • Noob
  • *
  • Posts: 21
  • Reputation: 3
intercepter-ios
« on: October 20, 2012, 07:25:59 am »
Hello everypne :). I'd like to show you guys a MITM tool I found for iOS.

The tool is called intercepter-ng. As previously stated, it is a MITM (man in the middle) tool and allows an attacker to sniff passwords, see live chat messages from clients such as Yahoo Messenger and Windows Live and much more. On the website (http://sniff.su/), this is the official list of features: (NOTE: features such as promiscuous mode are incompatible with the iPhone)
   
   + Sniffing passwords\hashes of the types:
       ICQ\IRC\AIM\FTP\IMAP\POP3\SMTP\LDAP\BNC\SOCKS\HTTP\WWW\NNTP\CVS\TELNET\MRA\DC++\VNC\MYSQL\ORACLE\NTLM
    + Sniffing chat messages of: ICQ\AIM\JABBER\YAHOO\MSN\IRC\MRA
    + Reconstructing files from:  HTTP\FTP\IMAP\POP3\SMTP\SMB
    + Promiscuous-mode\ARP\DHCP\Gateway\Smart Scanning
    + Capturing packets and post-capture (offline) analyzing\RAW Mode
    + Remote traffic capturing via RPCAP daemon
    + NAT\SOCKS\DHCP
    + ARP\DNS over ICMP\DHCP\SSL\SSLSTRIP\WPAD\SMBRelay MiTM\DNS Spoofing


I'm sure many of you have at least heard of it, since it is quite popular on Windows and is included in the Backtrack suite. I have personally been using this on Windows and Backtrack since some time last year. But today, after finally updating my Backtrack, I took a look at the intercepter-ng folder and noticed intercepter_ios. I then took a look at the readme (http://ge.tt/9pbmYsP/v/0) and noticed it offered instructions for installation on iOS :D.


INSTALLATION AND USAGE:
-----------------------------------

(either follow this guide http://www.villacorp.com/blog/2012/09/spying-live-messenger-msn-on-iphone-ipad/
or just read how I put it on [really simple])

1. Make sure you have libpcap from Cydia installed (you most probably will have it if you have any tools from the iNinjas repo)
2. download intercepter_ios http://ge.tt/86ybasP/v/0
3.  SSH into your device (or use iFile) and move intercepter_ios into your destination of choice. Mine is in /var/mobile/pentest/exploits/
4. Open mobile Terminal, login as root, browse to the location of intercepter_ios and type the following: chmod +x intercepter
5. run it by typing " ./intercepter_ios -h " (or for the GUI, leave the '-h', but I don't advise this as it doesn't work nicely on iPhone)
6. From here on, usage is simple. You will have a list of interfaces. en0 should be 1, so to run intercepter on en0 to sniff traffic including plaintext passwords, type " ./intercepter -ng 1 1 "
7. it will now do it's job  ;D

Here is the README: http://ge.tt/9pbmYsP/v/0
Here is intercepter_ios: http://ge.tt/86ybasP/v/0
Here is the official website: http://sniff.su/
Here are some screenshots of my iPhone sniffing passwords and normal traffic: http://imgur.com/a/a3kzY

It's also compatible with Android, so it can be cross-posted to the Android section too if anyone wants :)


[null]

  • Hero Member
  • *****
  • Posts: 646
  • Reputation: 42
  • the halloween jack is a real cool cat
  • Computers: I have a PC running Windows 7 that was built by my uncle. I also have a Newsmy T3 Android Tablet.
  • iDevices: iPod Touch 4G
Re: intercepter-ios
« Reply #1 on: October 20, 2012, 07:33:42 am »
Wow!! Awesome find and tut! This looks awesome! +1!
__  __           ___    ___          
/\ \/\ \         /\_ \  /\_ \          
\ \ `\\ \  __  __\//\ \ \//\ \     
 \ \ , ` \/\ \/\ \ \ \ \  \ \ \          
  \ \ \`\ \ \ \_\ \ \_\ \_ \_\ \_
   \ \_\ \_\ \____/ /\____\/\____\
    \/_/\/_/\/___/  \/____/\/____/

grinch

  • Administrator
  • Hero Member
  • *****
  • Posts: 1926
  • Reputation: 187
  • the digital grinch who stole your data
    • @DigitalGrinch
  • Badges:
  • iDevices: iPhone 3GS 4.3.3, HTC Evo V 4G ICS
Re: intercepter-ios
« Reply #2 on: October 20, 2012, 08:50:17 am »
Why would they include iOS instructions? It is useless. Can not do any of those activities without Promisc
Can't do any of the sniffing, any of the capturing. The only thing it looks like you can do is reconstruct sessions, but since you can not capture them on the device, this is just making more work
If I help you or you appreciate my work, clicking that +1 button is the best thanks I could get.

My opinions are my own, you may agree or disagree with them, but they are only just that; opinions
For example: facebook is the microsoft of social networks

http://goo.gl/PiVjI

@DigitalGrinch
https://twitter.com/DigitalGrinch

I follow all iNinjas members back. PM me if I am not following you

alizanda

  • Noob
  • *
  • Posts: 21
  • Reputation: 3
Re: intercepter-ios
« Reply #3 on: October 20, 2012, 10:39:05 am »
@grinch Maybe try reading the entire post?

At the very least, it serves as an alternative to iPwn/Pirni Pro for sniffing traffic and credentials. It has less dependencies, which obviously makes life a lot easier and requires only one command to set the process into full, automated swing.

Try show me one tool for iPhone which allows a user to see a live stream of URLs accessed and credentials entered in a neat and understandable manner. I understand iPwn caters for this, but I have personally never had success to the extent that I have with intercepter.

And, again, if you read the entire post, you would have noticed that I mentioned it is also compatible with Android, Linux and Windows - in which case all the features will be usable.

If you don't like it, you have no reason to downplay it and moan. Maybe I am in the wrong because I posted it in iHacking instead of Hacking, but I assumed people would be more interested in the fact that an interesting tool is available for iOS and not the mainstream Operating Systems.

Please refer to: http://www.urbandictionary.com/define.php?term=Sandy%20Vagina
« Last Edit: October 20, 2012, 10:49:09 am by alizanda »

grinch

  • Administrator
  • Hero Member
  • *****
  • Posts: 1926
  • Reputation: 187
  • the digital grinch who stole your data
    • @DigitalGrinch
  • Badges:
  • iDevices: iPhone 3GS 4.3.3, HTC Evo V 4G ICS
Re: intercepter-ios
« Reply #4 on: October 20, 2012, 12:03:04 pm »
No, it will not capture of sniff. You need to put a network device in promiscuous mode in order for it to not ignore any packet not addressed to it. That is the definition of promiscuous mode.

Maybe if you actually tried this, you would realize how useless this is for iOS, instead of wasting your time commenting on my opinion.

I voice my opinions often. You do not have to agree with them, but watch your attitude and language
If I help you or you appreciate my work, clicking that +1 button is the best thanks I could get.

My opinions are my own, you may agree or disagree with them, but they are only just that; opinions
For example: facebook is the microsoft of social networks

http://goo.gl/PiVjI

@DigitalGrinch
https://twitter.com/DigitalGrinch

I follow all iNinjas members back. PM me if I am not following you

Don't like seeing ads? Click here to register!

Apetrick

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 3510
  • Reputation: 91
  • <Apetrick> lank is 1337
  • Badges:
  • iDevices: Ipod Touch 4g
Re: intercepter-ios
« Reply #5 on: October 20, 2012, 04:28:10 pm »
No, it will not capture of sniff. You need to put a network device in promiscuous mode in order for it to not ignore any packet not addressed to it. That is the definition of promiscuous mode.

Maybe if you actually tried this, you would realize how useless this is for iOS, instead of wasting your time commenting on my opinion.

I voice my opinions often. You do not have to agree with them, but watch your attitude and language
su
alpine
ifconfig en0 promisc
That usually works for me :/
<%a12danrulz> Idk, but doing a DoS from an apple device is like fighting a bear with a plastic spork

B0mb3d

  • Full Member
  • ***
  • Posts: 218
  • Reputation: 3
Re: intercepter-ios
« Reply #6 on: October 23, 2012, 09:11:14 pm »
do you know what port interceptor feeds to? id like to try sslstrip im only getting traffic

eh. no promisc huh -.-
« Last Edit: October 24, 2012, 12:13:44 am by B0mb3d »

B0mb3d

  • Full Member
  • ***
  • Posts: 218
  • Reputation: 3
Re: intercepter-ios
« Reply #7 on: October 26, 2012, 12:03:45 am »
i cant seem to get this working on the N900. i run chmod -x intercepter_linux and chmod 777 intercepter_linux and it still wont give the permissions denied

Apetrick

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 3510
  • Reputation: 91
  • <Apetrick> lank is 1337
  • Badges:
  • iDevices: Ipod Touch 4g
Re: intercepter-ios
« Reply #8 on: October 26, 2012, 08:01:40 am »
It should be chmod +x Unless your trying to make it give you that error.
<%a12danrulz> Idk, but doing a DoS from an apple device is like fighting a bear with a plastic spork

Intercepter

  • Noob
  • *
  • Posts: 20
  • Reputation: 9
Re: intercepter-ios
« Reply #9 on: October 31, 2012, 02:49:08 am »
Hello guys, im the author of intercepter-ng.

I would appreciate if questions will be asked on it's own forum.

Though, some notes here...

1. Nokia n900 runs on ARM processor, while intercepter_linux build on Intel. You have to try android build (it's ARM based).
2. Promisc mode != Monitor mode, learn it. Usual sniffing and arp poisoning is working on any iOS devices.
3. Interactive mode works perfect on any devices too, you just have to install ncurses (install mc from cydia).
4. Besides sniffing passwords and chat messages it reconstructs complete files from network stream.


« Last Edit: October 31, 2012, 02:55:13 am by Intercepter »
Intercepter-NG - http://sniff.su

Don't like seeing ads? Click here to register!

B0mb3d

  • Full Member
  • ***
  • Posts: 218
  • Reputation: 3
Re: intercepter-ios
« Reply #10 on: October 31, 2012, 08:11:59 pm »
android didnt work either.

no avail on n900..but confirmed on SGSII. had to revert back to cm9 ics from jellybean though -.-
« Last Edit: November 07, 2012, 03:13:36 am by B0mb3d »

darrenliew96

  • Full Member
  • ***
  • Posts: 131
  • Reputation: 3
Re: intercepter-ios
« Reply #11 on: November 15, 2012, 06:55:21 am »
I thought that iOS have promisc mode via the worm repo? the edited version of network-cmds?
BTW can it sniff facebook password by stripping off the  HTTPS on the website?

Apetrick

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 3510
  • Reputation: 91
  • <Apetrick> lank is 1337
  • Badges:
  • iDevices: Ipod Touch 4g
Re: intercepter-ios
« Reply #12 on: November 15, 2012, 07:40:27 am »
I thought that iOS have promisc mode via the worm repo? the edited version of network-cmds?
BTW can it sniff facebook password by stripping off the  HTTPS on the website?
The network-cmds works from the ininjas repo to.
<%a12danrulz> Idk, but doing a DoS from an apple device is like fighting a bear with a plastic spork

Intercepter

  • Noob
  • *
  • Posts: 20
  • Reputation: 9
Re: intercepter-ios
« Reply #13 on: November 15, 2012, 11:10:21 am »
I thought that iOS have promisc mode via the worm repo? the edited version of network-cmds?
BTW can it sniff facebook password by stripping off the  HTTPS on the website?


there are no problems with promisc mode, it works just fine.
before asking a question about intercepter's functionality at least check description, intercepter-ng console edition do not
strip ssl.
Intercepter-NG - http://sniff.su

Pasky

  • Jr. Members
  • **
  • Posts: 52
  • Reputation: 2
  • iDevices: iPhone 4 iOS 4.1
Re: intercepter-ios
« Reply #14 on: December 06, 2012, 05:18:27 am »
Thank-you  i've been having fun with it for the past month and yes it captures everything except ssl and i never had to promisc dont know why !
What i usualy do is  save all the pcap files than when home i slide it over intercepter-ng  for windows and see all parsing credentials  !