<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; arp</title>
	<atom:link href="http://hackaday.com/tag/arp/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 06:18:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; arp</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Plug-in module lies about news at coffee shops. Real or Fake?</title>
		<link>http://hackaday.com/2011/02/19/plug-in-module-lies-about-news-at-coffee-shops-real-or-fake/</link>
		<comments>http://hackaday.com/2011/02/19/plug-in-module-lies-about-news-at-coffee-shops-real-or-fake/#comments</comments>
		<pubDate>Sat, 19 Feb 2011 14:35:31 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[wireless hacks]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[newstweek]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=35192</guid>
		<description><![CDATA[[Mike] sent in a tip about Newstweek, and we&#8217;re turning to our readers to tell us if this is real or if we&#8217;re being trolled. The link he sent us points to a well-written news-ish article about a device that plugs into the wall near an open WiFi hotspot and performs something of a man-in-the-middle attack on devices [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=35192&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-35193" title="news-changed-through-man-in-the-middle" src="http://hackadaycom.files.wordpress.com/2011/02/news-changed-through-man-in-the-middle-e1297905270638.jpg" alt="" width="470" height="353" /></p>
<p>[Mike] sent in a tip about Newstweek, and we&#8217;re turning to our readers to tell us if this is real or if we&#8217;re being trolled. <a href="http://newstweek.com/2011-01-07-device-distorts-news-on-wireless-neworks">The link he sent us</a> points to a well-written news-ish article about a device that plugs into the wall near an open WiFi hotspot and performs something of a man-in-the-middle attack on devices connected to the access point. The article describes the device above as it observes, then spoofs the ARP table of the wireless network in order to inject fake news stories in pages you are reading. Apparently once it boots, the small box phones home for commands from its maker over a TOR connection.</p>
<p>The box reminds us of the <a href="http://hackaday.com/2010/02/08/guruplug-the-next-generation-of-sheevaplug/">Sheevaplug</a> so it&#8217;s not the hardware that makes us question the possibility of the device. But look at the Linux terminal screen readout. It shows a prompt with the word &#8216;newstweek&#8217; in it. That&#8217;s the address of the site the article is hosted on, giving us a strong sense of being trolled.</p>
<p>What do you think, real or fake? Let us know (and why you think that) in the comments.</p>
<br />Filed under: <a href='http://hackaday.com/category/wireless-hacks/'>wireless hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/35192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/35192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/35192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/35192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/35192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/35192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/35192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/35192/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=35192&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2011/02/19/plug-in-module-lies-about-news-at-coffee-shops-real-or-fake/feed/</wfw:commentRss>
		<slash:comments>60</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2011/02/news-changed-through-man-in-the-middle-e1297905270638.jpg" medium="image">
			<media:title type="html">news-changed-through-man-in-the-middle</media:title>
		</media:content>
	</item>
		<item>
		<title>ARP poisoning is still a problem</title>
		<link>http://hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/</link>
		<comments>http://hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 01:00:00 +0000</pubDate>
		<dc:creator>Juan Aguilar</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[arppoisoning]]></category>
		<category><![CDATA[arpspoofing]]></category>
		<category><![CDATA[hdmoore]]></category>
		<category><![CDATA[layer2]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[mitm]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/04/arp-poisoning-is-still-a-problem/</guid>
		<description><![CDATA[You&#8217;ve no doubt heard that the site hosting Metasploit, the exploit framework, was hacked earlier this week, but what you may not have heard is that it was done using a layer 2 attack. Though Metasploit.com was not actually cracked, a server on the same VLAN was compromised and used to ARP poison the gateway. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1925&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img vspace="4" hspace="4" border="0" src="http://hackadaycom.files.wordpress.com/2008/06/had-metasploit-hacked-1.jpg" alt="" /><br />You&#8217;ve no doubt heard that the site hosting Metasploit, the exploit framework, was <a href="http://seclists.org/fulldisclosure/2008/Jun/0011.html">hacked earlier this week</a>, but what you may not have heard is that it was done <a href="http://taosecurity.blogspot.com/2008/06/old-school-layer-2-hacking.html?showComment=1212545100000#c7102389871482079713">using a layer 2 attack</a>. Though <a href="http://metasploit.com/">Metasploit.com</a> was not actually cracked, a server on the same VLAN was compromised and used to ARP poison the gateway. <a href="http://en.wikipedia.org/wiki/ARP_poisoning">ARP poisoning</a> is a method of sniffing data by sending a false ARP message to an Ethernet router to associate the hacker&#8217;s MAC address with a valid IP address from a genuine network node. From there the hackers were able to mount their MITM attack and show the image above instead of Metasploit&#8217;s website. This problem could have been avoided if the ISP was using fixed ARP entries, which is what [HD Moore] had to do to get the site back online. [Richard Bejtlich] points out that even though most people have been focusing on application security lately, <a href="http://taosecurity.blogspot.com/2008/06/old-school-layer-2-hacking.html?showComment=1212545100000#c7102389871482079713">fundamental attacks like this still happen</a>. If you&#8217;re doing a good job protecting yourself, you can still be at the mercy of the security of 3rd parties when operating in shared hosting environments.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/1925/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/1925/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/1925/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1925&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">juanaguilar</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had-metasploit-hacked-1.jpg" medium="image" />
	</item>
	</channel>
</rss>
