資訊安全概論 HW2
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
ARP Spoofing
Address Resolution Protocol,將IP位置對應到實體(MAC)位置的協定,查詢者會會發出ARP request,詢問網域內有誰match到該IP,被match到的人發回ARP reply,告訴查詢者「我是這個IP,然後我mac address是…」,接著查詢者收到後會建立arp表,之後要再往該IP丟封包時就可以不用再問mac address了。
而ARP Spoofing就是攻擊者先用NMAP找到目標(通常為gateway)傳送偽造的ARP reply封包,欺騙受害者該IP對應到的是攻擊者的mac,讓受害者傳往該IP的封包都傳送到攻擊者這,接著攻擊者再透過IP轉發把封包轉給該IP真正所在地,神不知鬼不覺的竊聽二者的通訊。
$ arpspoof -i {NIC card} –t {victim IP} {Gateway IP)
用-i指定網路介面,-t指定受欺騙的機器,後面接著gateway的IP。
DHCP Spoofing
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
一個網段裡通常會有DHCP伺服器,自動為新加入的機器分配IP、Gateway、net mask等設定,過程有四步驟,如下圖:
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
而DHCP Spoofing利用了DHCP request是廣播封包的特性,在收到DHCP request時搶先發出DHCP offer給victim,而其中就包含了錯誤的資訊,如將Gateway設為自己,以便聽取封包,之後再將該封包轉往真正的gateway。DHCP Snooping
Image Not Showing
Possible Reasons
- The image file may be corrupted
- The server hosting the image is unavailable
- The image path is incorrect
- The image format is not supported
Learn More →
為了防止上述的DHCP Spoofing行為,近代的switch設備上常有DHCP snooping的選項,能夠在建置網路時將連接真正DHCP的port設為trusted port,任何DHCP協定的封包只能由trusted port進入,untrusted port會drop掉所有DHCP offer,而DHCP snooping database側錄了DHCP Server給予的租用IP,負責從中控管有沒有不合法的流量。