This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+29 -30
View File
@@ -7,18 +7,18 @@
![1647096411.png](img/1647096411.png)
- IP is connection-less and state-less
- Best effort service
- No delivery guarantee
- No order guarantee
- Best effort service
- No delivery guarantee
- No order guarantee
- IPv4 No guaranteed security support
- IPv6 security support is guaranteed - IPSec
#### IPSec
- Optional in IPv4, mandatory support in IPv6
- Optional in IPv4, mandatory support in IPv6
- Two major security mechanisms
- IP Authentication Header (AH)
- IP Encapsulation Security Payload (ESP)
- IP Authentication Header (AH)
- IP Encapsulation Security Payload (ESP)
- Does not contain any mechanisms to prevent traffic analysis
##### Encapsulation Security Payload
@@ -31,7 +31,7 @@
- Stores security parameters e.g. crypto protocol and keys
- Established by Internet Security association and key management protocol (ISAKMP) during the Internet Key Exchange (IKE) handshake
- Uses Diffie-Hellman for key exchange
- Uses Diffie-Hellman for key exchange
- The SPI references the entry in a table that corresponds to this session’s parameters
- ESP uses either *transport* or *tunnel* modes
@@ -60,14 +60,14 @@ Tunnel mode
#### ARP
- ARP is a protocol used to obtain physical MAC addresses for given IPs
- It is used prior to constructing IP and TCP packets for communication
- Network layer
- It is used prior to constructing IP and TCP packets for communication
- Network layer
![1647097704.png](img/1647097704.png)
##### ARP Cache Poisoning
- We can simply send an unrequested ARP reply, and overwrite the MAC address in a hosts ARP cache with our own
- We can simply send an unrequested ARP reply, and overwrite the MAC address in a host’s ARP cache with our own
![1647097845.png](img/1647097845.png)
@@ -75,14 +75,14 @@ Tunnel mode
- Some OSs ignore unsolicited ARP requests, or can be configured to use ARP differently
- Some software, such as intrusion detection packages, will include ARP spoofing detection
- Maintain a log of current MAC:IP assignments and ARP requests / replies
- Maintain a log of current MAC:IP assignments and ARP requests / replies
#### DNS
- DNS translates domain names into IP addresses
- DNS packets are UDP
- Stateless on the transport layer
- DNS resolvers will cache the IP for awhile
- Stateless on the transport layer
- DNS resolvers will cache the IP for a while
##### DNS Spoofing
@@ -99,24 +99,24 @@ Tunnel mode
### Denial of Service
- A denial of service attack is an attempt to make a machine or network resource unavaliable to its authorised / intended users
- This will usually involve flooding a machine with enough requests that it can’t server its legitimate purpose
- ping flood
- A denial of service attack is an attempt to make a machine or network resource unavailable to its authorised / intended users
- This will usually involve flooding a machine with enough requests that it can’t serve its legitimate purpose
- ping flood
- A distributed denial of service occurs where there is more than one attacking machine
#### TCP Syn Flooding
- Attacker initiates a genuine connection but then immediately breaks it
- Attack never finishes 3-way handshake
- Attack never finishes 3-way handshake
- Victim is busy with the timeout
- Attack initiates large number of syn requests
- Victim reaches it’s half-open connection limit
- Victim reaches its half-open connection limit
![1647104111.png](img/1647104111.png)
#### Amplification Attacks
- Regular attacks are your bandwidth vs your targets
- Regular attacks are your bandwidth vs your target’s
- Amplification attacks utilise some aspect of a network protocol to *increase the bandwidth* of an attack
![1647104236.png](img/1647104236.png)
@@ -136,26 +136,25 @@ Tunnel mode
![1647104517.png](img/1647104517.png)
- In an ideal world, all DNS resolvers would:
- Use an authorised list of requesters
- e.g. ISPs allowing requests from only their customers
- Egress filtering
- Use an authorised list of requesters
- e.g. ISPs allowing requests from only their customers
- Egress filtering
- Many DNS servers are set up incorrectly, and will happily amplify your traffic - **Open resolvers**
- Botnets maintain lists of these open resolvers and there are projects attempting to shut these down
##### NTP Amplification
- NTP is a protocol for synchronsing time between machines
- NTP is a protocol for synchronising time between machines
- Extremely similar to DNS amplification
- `MON_GETLIST` request returns the list of the last 600 contacts
- Gives 200x amplification
- `MON_GETLIST` is deprecated because of this attack
- `MON_GETLIST` request returns the list of the last 600 contacts
- Gives 200x amplification
- `MON_GETLIST` is deprecated because of this attack
##### Slow Loris
- Opens numerous connections to a server
- Begin an HTTP request
- Send just enough traffic to stop the connection from closing
- Apache2 creates a new thread for each connection
- More connections slow the server down significantly
- Send just enough traffic to stop the connection from closing
- Apache2 creates a new thread for each connection
- More connections slow the server down significantly
- The attack only sends bytes of data at a time making it extremely easy to do