ARP欺骗后目标虚拟机断网问题的排查与修复请求
ARP欺骗后目标机无法联网的排查与解决方法
一、基础环境验证
- 确认Kali攻击机、Windows11目标机处于同一虚拟网络段,分别执行
ping [router_ip],确保两者都能正常连通路由器 - 在Kali终端执行
arping -c 2 [target_ip]和arping -c 2 [router_ip],验证是否能获取到目标机、路由器的MAC地址,排除MAC获取失败的问题 - 检查Kali的IP地址,确保与目标机、路由器在同一子网内,跨网段ARP欺骗大概率失效
二、脚本问题修复
1. 指定发送网卡
脚本默认不指定发送接口,可能导致数据包发送到错误网卡。修改spoof和restore函数的scapy.send命令,添加Kali的攻击网卡(比如eth0或tap0):
# spoof函数中修改send命令 scapy.send(packet, iface="eth0", verbose=False) # restore函数中修改send命令 scapy.send(packet_target, count=4, iface="eth0", verbose=False) scapy.send(packet_router, count=4, iface="eth0", verbose=False)
2. 完善ARP恢复逻辑
原脚本仅恢复目标机的ARP表,需补充路由器的ARP表恢复:
def restore(target_ip, router_ip): """Restore the original ARP tables of the target and router.""" target_mac = get_mac(target_ip) router_mac = get_mac(router_ip) # 恢复目标机的ARP表(写入路由器真实MAC) packet_target = scapy.ARP(op=2, pdst=target_ip, hwdst=target_mac, psrc=router_ip, hwsrc=router_mac) # 恢复路由器的ARP表(写入目标机真实MAC) packet_router = scapy.ARP(op=2, pdst=router_ip, hwdst=router_mac, psrc=target_ip, hwsrc=target_mac) scapy.send(packet_target, count=4, verbose=False) scapy.send(packet_router, count=4, verbose=False)
3. 提高欺骗包优先级
在spoof函数中增加发送次数,避免目标机/路由器的ARP表被原条目覆盖:
scapy.send(packet, count=2, verbose=False)
三、Kali转发配置重检
- 强制开启IP转发:执行
echo 1 > /proc/sys/net/ipv4/ip_forward,再用cat /proc/sys/net/ipv4/ip_forward确认输出为1 - 清空并重置iptables规则:
iptables -F iptables -X iptables -P INPUT ACCEPT iptables -P FORWARD ACCEPT iptables -P OUTPUT ACCEPT iptables -t nat -F
四、虚拟机网络模式调整
- 若使用NAT模式,macOS宿主可能拦截转发流量,建议将Kali和Windows11虚拟机均改为桥接模式,直接接入物理网络
- 在Kali开启网卡混杂模式:
ip link set dev eth0 promisc on(替换为实际网卡名),确保能捕获网段内所有流量
五、验证流程
- 运行脚本前,在Windows11执行
arp -a,记录路由器的真实MAC地址 - 启动脚本后,再次执行
arp -a,确认路由器的MAC已替换为Kali的MAC - 在Windows11执行
ping 8.8.8.8,同时在Kali用tcpdump -i eth0 icmp查看是否捕获到ICMP数据包,验证流量是否经过Kali
内容的提问来源于stack exchange,提问作者Iamspeed Mc
相关产品推荐
相关产品推荐

