Closed topazbor closed 8 years ago
I'll test more firewall scenarios with Tater after I get Inveigh 1.1 released.
maybe it will be nice to try to add arp spoffing for inveigh thanks
I'm not sure that the firewall is blocking you in this case. In my testing, it's the NBNS spoofer that triggers the firewall alert. With default setting, the spoofer is the only thing not using 127.0.0.1. In your screenshot, I can see that WPAD has been successfully spoofed so the NBNS spoofer has done its job. Here are a few things to try:
I have a couple of test systems that just don't seem to want to work anymore with either potato or tater and the Windows Defender trigger. I have not had a chance to really look into it.
I'm going through a cleanup round with Tater and will continue to test.
Great, I will test with -NBNS N and let you know what happened great job BTW
On Thu, Mar 17, 2016 at 4:23 AM, Kevin Robertson notifications@github.com wrote:
I'm not sure that the firewall is blocking you in this case. In my testing, it's the NBNS spoofer that triggers the firewall alert. With default setting, the spoofer is the only thing not using 127.0.0.1. In your screenshot, I can see that WPAD has been successfully spoofed so the NBNS spoofer has done its job. Here are a few things to try:
- Disable the firewall and see if it works
- Enable the firewall, delete whatever you are using (powershell or powershell_ise) from the firewall allowed list and start Tater with -NBNS N. You should not see a firewall prompt.
- If it always hangs at that same spot, open a browser and navigate to http://127.0.0.1. You should see an HTTP request notification from Tater. This will confirm that the HTTP listener is working.
- If the HTTP listener seems to be working, maybe try trigger 0 and just let it run for a day.
- Try potato.exe and see if it behaves the same. https://github.com/foxglovesec/Potato
I have a couple of test systems that just don't seem to want to work anymore with either potato or tater and the Windows Defender trigger. I have not had a chance to really look into it.
I'm going through a cleanup round with Tater and will continue to test.
— You are receiving this because you authored the thread. Reply to this email directly or view it on GitHub https://github.com/Kevin-Robertson/Tater/issues/3#issuecomment-197658161
you can close this subject
I have tried Tater, and for the first time I run it, it ask for a new windows firewall rule. And as you know, it require privileges for that. What do you think?