question on wifi

white88enochianwhite88enochian Regular
edited February 2012 in Tech & Games
if im on someones wifi is there a way i can see what sites they are on and what they are doin ect

also say if i changed the default password for the router settings could they reset the router and change the password back
i wouldnt want them to set a wireless password for the few days im here i plan on setting it back to default when i leave

also is there a way to find the username and password for some ones computer using there wireless router
i tryied the guest account but its disabled

Comments

  • RemadERemadE Global Moderator
    edited December 2011
    I used to do this with URLsniffer on Backtrack. There may be a Windows equivalent but I'm not too clued-up on the matter. Hopefully someone will shed some light on it :)
  • DfgDfg Admin
    edited December 2011
    Check for Trx100 guide on Wifi hacking.
  • edited December 2011
    1. To see the websites people are on and "what they are doin etc", you're gonna need a copy of Backtrack. It contains some tools - Arpspoof, driftnet, URLsnarf, MSGsnarf etc. Learn how to use the tools by looking at tutorials on the internet, or work it out as you're going along. I suggest watching this video;

    http://hak5.org/hack/arp-spoofing-with-dsniff

    2. If you change the password for the router config, yes, they can reset their router to factory settings and enter a new one. The idea here is to be SILENT - changing things is going to raise flags. Your best bet is to spoof your MAC address, and change your machine name to something appropriate. Nothing which will give you away, and nothing they'll think is unordinary should they decide to check to see who's connected to the AP (assuming they're not tech-savvy).

    3. As far as I'm aware, you won't be able to "see" a computer's username and password just by connecting to the AP. Imagine how insecure networks would be if that was the case! If you're looking to gain remote access to a computer, it's likely that you'll have to look for exploits on your target machine and take advantage of them. Read my Guide to Port Scanning with NMAP and my Introduction to Metasploit for some pointers.
  • white88enochianwhite88enochian Regular
    edited December 2011
    yeah i already have backtrack 4 and 5 my computer looks like a copy of there router the only reason i set a password to view the settings paige on the router is so they dont put a wpa password i know i can get into a wep
  • SlartibartfastSlartibartfast Global Moderator -__-
    edited December 2011
    If the website authentication is in plain text, you'll be able to see the password with wireshark and analyzing the http post/get requests. It often isn't so you'd have to do what Trx100 suggested.

    In regards to getting local computer passwords, occasionally you see network shares configured so badly that you are able to access the system32 folder. The passwords are all located in the SAM file. You could use OphCrack to crack them.


    http://etherape.sourceforge.net/
  • bornkillerbornkiller Administrator In your girlfriends snatch
    edited February 2012
    yeah i already have backtrack 4 and 5 my computer looks like a copy of there router the only reason i set a password to view the settings paige on the router is so they dont put a wpa password i know i can get into a wep
    You can crack wpa's with linux tools or BT ... More a pain in the ass than wep, but it can be done.
Sign In or Register to comment.