Penetration Testing mailing list archives

RE: Redirecting traffic


From: "Gautam Sarup" <gautamsarup () hotmail com>
Date: Sat, 06 Aug 2005 12:47:11 -0500

Perhaps 'rinetd' is what you are looking for.
http://www.boutell.com/rinetd/
-gautam

From: "Andres Molinetti" <andymolinetti () hotmail com>
To: pen-test () securityfocus com
Subject: Redirecting traffic
Date: Fri, 05 Aug 2005 17:28:38 +0000
MIME-Version: 1.0
X-Originating-IP: [64.4.51.220]
X-Originating-Email: [andymolinetti () hotmail com]
X-Sender: andymolinetti () hotmail com
Received: from outgoing.securityfocus.com ([205.206.231.27]) by mc8-f10.hotmail.com with Microsoft SMTPSVC(6.0.3790.211); Sat, 6 Aug 2005 09:35:04 -0700 Received: from outgoing.securityfocus.com by outgoing.securityfocus.com via smtpd (for mail2.hotmail.com [65.54.253.230]) with ESMTP; Sat, 6 Aug 2005 09:35:04 -0700 Received: from lists.securityfocus.com (lists.securityfocus.com [205.206.231.19])by outgoing3.securityfocus.com (Postfix) with QMQPid D5F0923A32D; Sat, 6 Aug 2005 09:39:32 -0600 (MDT)
Received: (qmail 17815 invoked from network); 5 Aug 2005 10:52:03 -0000
X-Message-Info: JGTYoYF78jGtTGcBXrnMMbw0Iw5S64Tb7qxVD9cvWrY=
Mailing-List: contact pen-test-help () securityfocus com; run by ezmlm
Precedence: bulk
List-Id: <pen-test.list-id.securityfocus.com>
List-Post: <mailto:pen-test () securityfocus com>
List-Help: <mailto:pen-test-help () securityfocus com>
List-Unsubscribe: <mailto:pen-test-unsubscribe () securityfocus com>
List-Subscribe: <mailto:pen-test-subscribe () securityfocus com>
Delivered-To: mailing list pen-test () securityfocus com
Delivered-To: moderator for pen-test () securityfocus com
X-OriginalArrivalTime: 05 Aug 2005 17:28:38.0753 (UTC) FILETIME=[1DDC4D10:01C599E3] Return-Path: pen-test-return-1078477461-gautamsarup=hotmail.com () securityfocus com

I am pen-testing a client application and I 've found, analysing traffic dumps, that it seems to connect to a hardcoded internal IP and retrieve data from a strange port that is afterwards displayed in the application. I want to be able to redirect that traffic to another IP in order to test it for overflows and other issues. I have found a way to change the default gateway of the application's host. So I thought of setting my linux box as its gateway and using iptables to redirect the traffic to the other IP.
I'm needing help with the building of the rules...

Thks,
Andy

_________________________________________________________________
Descubre la descarga digital con MSN Music. Más de medio millón de canciones. http://music.msn.es/


------------------------------------------------------------------------------
FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't

Learn the hacker's secrets that compromise wireless LANs. Secure your
WLAN by understanding these threats, available hacking tools and proven
countermeasures. Defend your WLAN against man-in-the-Middle attacks and
session hijacking, denial-of-service, rogue access points, identity
thefts and MAC spoofing. Request your complimentary white paper at:

http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
-------------------------------------------------------------------------------




------------------------------------------------------------------------------
FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't

Learn the hacker's secrets that compromise wireless LANs. Secure your
WLAN by understanding these threats, available hacking tools and proven
countermeasures. Defend your WLAN against man-in-the-Middle attacks and
session hijacking, denial-of-service, rogue access points, identity
thefts and MAC spoofing. Request your complimentary white paper at:

http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
-------------------------------------------------------------------------------


Current thread: