ARP Spoofing

ARP Spoofing (ARP Poisoning):

  1. 概述:A Man in the Middle attack that allows attackers to intercept communication between network devices
  2. 原理:
    • Attacker determine the IP addresses of at least two devices (let’s say a workstation and a router)
    • Attacker uses a spoofing tool (such as Arpspoof or Driftnet) to send out forged ARP responses, which advertise that the MAC address for the workstation and the router is the attacker’s MAC address
    • Then the router and workstation update their ARP cache entries, and future will communicate to the attacker’s machine, instead of to each other
      在这里插入图片描述
  3. Detect an ARP Cache Poisoning Attack
C:\Users\0701> arp -a

Internet Address    Physical Address

192.168.5.1        00-14-22-01-23-45
192.168.5.201      40-d4-48-cr-55-b8
192.168.5.202      00-14-22-01-23-45

如上述所示,若两个不同的IP地址有相同的MAC地址,就说明一个ARP attack发生了。
对于大型网络来说,要get到一些attack正在carry out的通信信息,可以使用Wireshark

  1. ARP Spoofing Prevention
    • 使用VPN:makes all communication encrypted, and worthless for an ARP spoofing attacker
    • 使用static ARP:define a static ARP entry for an IP address, and prevent devices from listening ARP responses for that address
    • 使用packet filtering:identify poisoned ARP packets by seeing that they contain conflicting source information, and stop them before they reach devices on your network
    • Run a spoofing attack:通过自己搞一个spoofing attack,来查看现有的defenses是否working
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值