Latest comments

In response to: Network Traffic Interception

Alecc Carlo Bertulfo [Visitor] · http://www.yagamiwebsite.blogspot.com
This is so cool... im very interested with this topic.... I'm so impressed with the Network Traffic Interception....
PermalinkPermalink 02/04/10 @ 02:35

In response to: Internet Speed Optimization

kghj [Visitor]
if you wanna optimize your internet performance, i suggest downloading dsl speed, it can boosts internet connection, thereby speeding up your computer
PermalinkPermalink 01/18/10 @ 20:46

In response to: My Top 10 Network Security Tools

Malakai [Visitor] · http://www.rapidsharemix.com
I think You do a great job. Thanks
PermalinkPermalink 12/24/09 @ 07:42

In response to: DNSWall – A Protection Mechanism against DNS Rebinding Attacks

john brightman [Visitor] · http://www.whoismark.com
HI
looks very interesting!
bookmarked your blog.
john brightman
PermalinkPermalink 05/25/09 @ 11:35

In response to: My Top 10 Network Security Tools

sarah willson [Visitor] · http://www.whoismark.com
Hi Thanks for security information! great article!
PermalinkPermalink 05/22/09 @ 16:16

In response to: Windows Vista and Proxy-ARP Requests

sexysex [Visitor]
I want a program to penetrate the proxy for Windows Vista
PermalinkPermalink 04/26/09 @ 09:59

In response to: Network Traffic Interception

Ruth [Visitor] · http://laptopmessengerbag.info
I recently came across your blog and have been reading along. I thought I would leave my first comment. I don't know what to say except that I have enjoyed reading. Nice blog. I will keep visiting this blog very often.

Ruth

http://laptopmessengerbag.info
PermalinkPermalink 03/27/09 @ 21:42

In response to: Network Traffic Interception

cool [Visitor]
cool
PermalinkPermalink 03/23/09 @ 09:28

In response to: EXTENDED DHCP Exhausting Attack

huku [Visitor] · http://www.grhack.net
Hello there,

I wonder why anyone would like to perform the DHCP exhausting attack while having access to the LAN of the target network. There's a feature of the DHCP protocol which allows for deceiving all the hosts in the subnet. Let's have a look at the relevant RFC :-)

--- snip rfc2131 ---
The server MAY choose to return the 'vendor class identifier' used to determine the parameters in the DHCPOFFER message to assist the client in selecting which DHCPOFFER to accept.
--- snip rfc2131 ----

And...

--- snip rfc2131 ---
Unauthorized DHCP servers may be easily set up. Such servers can then send false and potentially disruptive information to clients such as incorrect or duplicate IP addresses, incorrect routing information (including spoof routers, etc.), incorrect domain nameserver addresses (such as spoof nameservers), and so on. Clearly, once this seed information is in place, an attacker can further compromise affected systems.
--- snip rfc2131 ---

So, it's quite obvious. Just send fake DHCP replies to all the hosts in the subnet and force them to think that you are the gateway and the DNS server for the LAN. From there on, you can perform other attacks (e.g DNS spoofing, SSL MiM etc).

There's only one problem left. How can one force the client to choose _their_ DHCP offer instead of the legitimate one. Well... It's just a matter of providing fake options. The client will pick up the answer that satisfies all of the requested options (and that's the reason that various DHCP servers can be used for various client classes in the same LAN).

Anyway, good work :-). I'd just like to point out that your extended DHCP attack will not work on properly configured gateways. Usually, sane administrators choose to drop any packet with a source IP address that doesn't match the netmask of the incoming interface and packets that have source IP equal to the gateway's (just have a look at the BSD pf antispoof rules).

Cheers
./hk
PermalinkPermalink 12/13/08 @ 08:27

In response to: Giant-Reverse: The Next Gen. Reverse Shell

RocknRoll [Visitor] · http://techstud.org
Nice Info about reverse shell execution...
with neat English ...

Keep it up buddy...
PermalinkPermalink 12/10/08 @ 18:43

In response to: My Top 10 Network Security Tools

funkinessflavor [Visitor]
90% agree (scapy is missing !)
PermalinkPermalink 12/03/08 @ 09:33
September 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

This is the Blog of Securebits Think-Tank. It is maintained by AR Samhuri. The blog is about topics like Network Security, Penetration Testing, TCP/IP Attacks, Security R&D, Security Tools, etc.

Search

XML Feeds

free blog software