Does not show passwords (regression because of (Debian) patch)

Bug #624547 reported by Meluco
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ettercap (Debian)
Fix Released
Unknown
ettercap (Ubuntu)
Fix Released
High
Unassigned

Bug Description

Binary package hint: ettercap

'ettercap -T -q -M arp /victim1/ /victim2/' must show http or ftp passwords in screen, but there isn't.

'ettercap -T -Q -M arp /victim1/ /victim2/ -w /tmp/file.pcap' and then 'ettercap -T -q -r /tmp/file.pcap' do the same.

If I open /tmp/file.pcap with Whireshark and search password string manualy, I find it.

Revision history for this message
Mark Doliner (thekingant) wrote :

This might be caused by the patch from http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521857 The first proposed patch from the Debian ticket also exists in the Ubuntu package, and I believe it is incorrect. I'm seeing a similar problem to the one described by Meluco--ettercap's TCP analyzer is seemingly unable to capture or log traffic.

Making either of the changes suggested by the last few comments on the Debian ticket (change the int to either long or u_char) fix the problem for me. Although I wasn't able to test whether ettercap crashed, as I have not experienced the described crash myself.

Daniel Hahler (blueyed)
Changed in ettercap (Ubuntu):
status: New → Triaged
importance: Undecided → High
summary: - Don't show passwords on screen
+ Does not show passwords (regression because of (Debian) patch)
Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

@Mark Doliner, could you explain better your solution?

is only changing from (int) to (long) ???

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

This bug should be fixed in 0.7.3-2.1ubuntu2 (ubuntu Oneiric and Precise).

Could anybody give it a try?

tags: added: verification-needed
Revision history for this message
Meluco (daniel-banobre-dopico) wrote : Re: [Bug 624547] Re: Does not show passwords (regression because of (Debian) patch)

El jue, 27-10-2011 a las 16:03 +0000, LocutusOfBorg escribió:

> This bug should be fixed in 0.7.3-2.1ubuntu2 (ubuntu Oneiric and
> Precise).

It's fixed in 1:0.7.3-2.1ubuntu1 (natty) x86_64.

>
> Could anybody give it a try?
>
> ** Also affects: ettercap (Debian) via
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521857
> Importance: Unknown
> Status: Unknown
>
> ** Tags added: verification-needed
>

Changed in ettercap (Ubuntu):
status: Triaged → Fix Released
tags: added: verification-done
removed: verification-needed
tags: removed: verification-done
Changed in ettercap (Debian):
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.