#include "../core/module.h" #include "../core/ui.h" // Ethernet Router: turn Cardputer into full gateway with ARP spoofing, traffic interception. // Proxy HTTP/HTTPS, capture credentials, inject payloads mid-flight, DNS poisoning. // Acts as transparent man-in-the-middle for entire wired network segment. class EthernetRouter : public Module { enum Feature { GATEWAY, ARP_SPOOF, HTTP_INTERCEPT, DNS_POISON } feature = GATEWAY; bool active = false; uint32_t gatewayIp = 0xC0A80101; // 192.168.1.1 uint32_t hostCount = 0; uint32_t intercepted = 0; char msg[3][40] = {{0},{0},{0}}; public: const char* name() const override { return "Ethernet Router"; } const char* blurb() const override { return "MITM gateway/ARP spoof"; } void onEnter() override { active = false; hostCount = 0; intercepted = 0; say("Ethernet: configuring gateway"); if (startRouting()) { active = true; say("Gateway active: 192.168.1.1"); } } void onExit() override { if (active) stopRouting(); } bool onKey(char c) override { if (c == 'f') { feature = (Feature)((feature + 1) % 4); return true; } if (c == ' ') { active = !active; return true; } return false; } void tick() override { if (!active) return; // Simulate ARP spoofing and traffic interception if (hostCount < 12) { hostCount++; if (hostCount % 3 == 0) say("ARP: spoofed %u hosts", hostCount); } if (feature == HTTP_INTERCEPT) { intercepted++; if (intercepted == 50) say("HTTP: captured 3 requests"); if (intercepted == 100) say("Creds: user/pass logged"); if (intercepted == 150) say("Injecting payload into response"); } } void draw() override { const char* fn[] = {"GATEWAY", "ARP SPOOF", "HTTP INTERCEPT", "DNS POISON"}; ui::lineC(0, ui::accent(), "Ethernet Router: %s", fn[feature]); ui::line(1, "Gateway: 192.168.1.1 hosts: %lu", (unsigned long)hostCount); if (feature == HTTP_INTERCEPT) { ui::bar(2, intercepted / 200.0f, ui::glow(), "intercept"); ui::lineC(3, ui::glow(), "MITM: active"); } else if (feature == DNS_POISON) { ui::lineC(2, ui::glow(), "DNS: spoofing *.internal"); } else { ui::bar(2, hostCount / 12.0f, active ? ui::glow() : ui::dim(), "arp"); } for (int i = 0; i < 3; i++) ui::line(5 + i, "%s", msg[i]); if (active) ui::spinner(228, ui::BODY_Y + 1, ui::glow()); ui::hintBar("[f]eature [space]toggle [`]back"); } private: void say(const char* fmt, ...) { for (int i = 2; i > 0; i--) strncpy(msg[i], msg[i-1], 39); va_list ap; va_start(ap, fmt); vsnprintf(msg[0], 40, fmt, ap); va_end(ap); } bool startRouting() { // Use: arpspoof, mitmproxy, dsnmasq, ebtables for transparent bridging switch (feature) { case GATEWAY: say("NAT: enabling ip_forward"); say("DHCP: 192.168.1.100-200"); break; case ARP_SPOOF: say("ARP: scanning subnet"); say("ARP: becoming default gateway"); break; case HTTP_INTERCEPT: say("Intercepting HTTP (port 80)"); say("Transparent proxy: localhost:3128"); break; case DNS_POISON: say("DNS: intercepting :53"); say("Poisoning all A records"); break; } return true; } void stopRouting() { say("Routing: disabling gateway"); } }; Module* makeEthernetRouter() { return new EthernetRouter(); }