Skip to main content

MAN-IN-THE-MIDDLE ATTACK (MITM ATTACK)

What is Man-in-the-middle (MITM) attack?
A man in the middle attack is one in which the attacker intercepts messages in a public key exchange and then retransmits them, substituting his own public key for the requested one, so that the two original parties still appear to be communicating with each other.
The attack gets its name from the ball game where two people try to throw a ball directly to each other while one person in between them attempts to catch it. In a man in the middle attack, the intruder uses a program that appears to be the server to the client and appears to be the client to the server. The attack may be used simply to gain access to the message, or enable the attacker to modify the message before retransmitting it.
Man in the middle attacks is sometimes known as fire brigade attacks. The term derives from the bucket brigade method of putting out a fire by handing buckets of water from one person to another between a water source and the fire.
What is BackTrack Linux?
Backtrack is a Linux distribution distributed as Live cd or Usb for penetration testing. BackTrack provides penetration testers a comprehensive collection of security related tools, support live cd and live usb and permanent installation also. BackTrack provides Mozilla, Pidgin, K3B, XMMS .You can create personalized distributions by including customizable scripts, additional tools and configurable kernels.

BackTrack includes many well known security tools Like NMAP, KISMET and many more.
Backtrack 5 has been released and based on ubuntu 11.04. Backtrack 5 contains most of the security audit tools for penetration testing purpose. Backtrack 5 with all the tools are free of cost.
Preparation for MITM Attack
We need to identify the victim’s IP for the attack. We need two IP addresses in which we will be the Man in the middle. We can use nmap scan which have already cover in the previous tutorials. Use the nmap to scan the whole network and identify the victim clearly. Another method we have is to consider the whole network as victim. If we will select two particular victim’s IPs then we will be able to see packets only between those two IP address but if we will choose whole network to be the victim the every packet floating in the network will be relayed from the attacker’s machine.
See the ettercap tutorial for configuring ettercap for this attack.
Ettercap demo
A separate PDF has been attached to demonstrating the MITM attack using ettercap. Please go through the PDF for learning the MITM Attack.
Countermeasures against "man in the middle" attacks
What protections are there against man in the middle attacks on your network? Consider these steps:
o Survey the APs operating with your unique SSID. Take down any that are not authorized to be on the air.
o Use strong encryption on your network. WPA is much better than WEP
o Use SSL. It will make man in the middle attacks more difficult, and will prevent most attacks.
o Double-check SSL certificates before using https pages. IE and Firefox can do this for you.
o Encrypt any documents you don't want to be intercepted or altered.
o Using a VPN service is quite effective against man in the middle attacks


o Forget about WEP. WEP is dead. Use WPA encryption

Comments

Popular posts from this blog

NMAP and ZenMAP

NMAP and ZenMAP are useful tools for the scanning phase of Ethical Hacking in Kali Linux. NMAP and ZenMAP are practically the same tool, however NMAP uses command line while ZenMAP has a GUI. NMAP is a free utility tool for network discovery and security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. NMAP uses raw IP packets in novel ways to determine which hosts are available on the network, what services (application name and version) those hosts are offering, which operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, etc. Now, let’s go step by step and learn how to use NMAP and ZenMAP. Step 1 − To open, go to Applications → 01-Information Gathering → nmap or zenmap. Step 2 − The next step is to detect the OS type/version of the target host. Based on the help indicated by NMAP, the parameter of

networks nd networking 1

Types Of Network •LAN - Local Area Network is in a small geographical area, such as a college or office building. •WAN - Wide Area Network Combination of multiple LANs. •WLAN - Wireless Local Area Network Links two or more devices using some wireless distribution method and usually providing a connection through an access point to the wider internet. Local Area Network (LAN) •A LAN connects network devices within a limited geographical area such as office buildings or schools. •The data transfer is managed by a transport protocol such as TCP/IP. •The transmission of data is performed by the access method (Ethernet, Token Ring, etc.). Wide Area Network (WAN) •A WAN covers a wide geographic area, carrying data over long distances, such as a country •WANs can be formed by different LANs •The connection between different LANs may not be permanent •WANs are sophisticated networks, but transmission speeds have generally been slower than those commonly achieved on LANs WLAN (Wireles

TOP 10 HIGHEST-PAYING JOBS IN TECH

πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’°πŸ’° πŸ’ΈTOP 10 HIGHEST-PAYING JOBS IN TECHπŸ’Έ πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘πŸ€‘ πŸ”Ÿ. Information security engineer: $131,300 An information security engineer works to protect the company's data and other assets from hackers and other malicious parties. That could be through strengthening encryption or generally working to close any security gaps in the company's infrastructure. 9⃣. DevOps engineer: $137,400 A DevOps (development and operations) engineer is a specialized role that involves delivering a lot of code, quickly. 8⃣. Enterprise architect: $144,400 An enterprise architect develops the plans and workflows for deploying and maintaining servers, software, and other IT assets. In other words, an enterprise architect is on the hook to come up with (or at least, contribute to) the IT strategy. 7⃣. Technical program manager: $145,000 A technical program manager will keep tabs on the various projects throughout the company, test codes, lay out product expectations,