By: xpfox
China Telecom in various regions is currently trying to promote the advertisement software developed by China Telecom, which is based on the sky. Taking a closer look, he is useless to improve user security!
In this case, the PPPoE dial-up program under xp is not separated. You can find that two new connections are created under the xp dial-up connection while installing the software. They are not set to store passwords. The main function of a rogue client is to generate encrypted user dialing information, and fill in the dialing program under xp to establish dialing.
Therefore, we can get the user dialing Information encrypted by the rogue software.
Since the rogue software still uses the PPPoE protocol, we can use the packet capture software on the dial side to intercept the PPPoE information sent through the machine Nic.
Mainly used software:
WildPackets OmniPeek
Start Software
Select New Capture
Select the NIC connected to the adsl Router
Start the dipper. Please do not use it to dial at this time.
Start the software and click Start Capture.
In this case, use the space-based dial-up method.
Stop software packet capture
Get the picture
Select the first data packet whose protocol value is password authentication
Double-click to open
View
The Peer-Id and Passwd values correspond to the user name and password for dialing.
Use these two values to create a new dial and discard the Star software.
Encryption rules
Submitted by the region encryption rule
Xiantao region, Hubei Province ~ D XpFox
Hubei Ezhou region ~ I giit when weeping
Hubei Ezhou region ~ 3.
Yichang, Hubei Province ~ Kheja
Hubei Yichang Xiling ~ H xxtameng
Hubei Yichang Yiling ~ J yivhang
Hubei Tianmen duoxiang ~ 5 or ~ N old thieves
Suizhou, Hubei Province ~ H Suizhou's
Usage:
For example, add ~ D. The password remains unchanged. For example, the original account is hbxt3333333 and changed ~ Dhbxt3333333 password unchanged
Collection is underway elsewhere. I hope you can capture the user name and password according to the above method and provide overlord rules in various places to facilitate internet access.