From charlesreid1

 
(5 intermediate revisions by 2 users not shown)
Line 3: Line 3:
Layer 4 = Transport (TCP protocol, packets)
Layer 4 = Transport (TCP protocol, packets)


=Conducting Recon=
=Attack Steps=
 
==Conducting Recon==


Before carrying out any attacks, conduct recon. This is nmap territory. Here are some things you'll want to know:
Before carrying out any attacks, conduct recon. This is nmap territory. Here are some things you'll want to know:
Line 11: Line 13:
* Etc.
* Etc.


=Layer 3 Attacks=
==Layer 3 Attacks==


{{Main|Kali/Layer 3 Attacks}}
{{Main|Kali/Layer 3 Attacks}}


Port Stealing - [[Man in the Middle/Wired/Port Stealing]]
Traffic Sniffing: [[Man in the Middle/Sniffing]]


DHCP Spoofing - [[Man in the Middle/Wired/DHCP Spoofing]]
ARP Poisoning: [[Man in the Middle/ARP Poisoning]] {{,}} [[Man in the Middle/Wired/ARP Poisoning]]


NDP Poisoning  - [[Man in the Middle/Wired/NDP Poisoning]]
NDP (IPv6 equivalent of ARP) Spoofing: [[Man in the Middle/NDP Spoofing]]


=Layer 4 Attacks=
Port Stealing: [[Man in the Middle/Port Stealing]]


{{Main|Kali/Layer 4 Attacks}}
Rushing Attack: [[Man in the Middle/Rushing Attack]]


CAM list overflow
==Layer 4 Attacks==


DHCP attacks
{{Main|Kali/Layer 4 Attacks}}


Rushing attack
DHCP Attack: [[Man in the Middle/DHCP]]


=Dealing with Encryption=
SSL Attacks: [[SSLStrip]] {{,}} [[SSLSniff]] {{,}} [[Certificates]]


Tools and techniques for dealing with SSL/TLS/other encryption methods
=Tools=


[[SSLStrip]]
<s>[[Ettercap]]</s>


=Tools=
[[Bettercap]]


[[Dsniff]]
[[Dsniff]]


[[SSLStrip]]
[[SSLStrip]]
[[SSLSniff]]


=Flags=
=Flags=


{{MITMFlag}}
{{MITMFlag}}

Latest revision as of 20:37, 5 March 2022

Layer 3 = Network (IP protocol, packets)

Layer 4 = Transport (TCP protocol, packets)

Attack Steps

Conducting Recon

Before carrying out any attacks, conduct recon. This is nmap territory. Here are some things you'll want to know:

  • Number of clients on network
  • Open ports, services running
  • Operating systems
  • Etc.

Layer 3 Attacks

Traffic Sniffing: Man in the Middle/Sniffing

ARP Poisoning: Man in the Middle/ARP Poisoning  · Man in the Middle/Wired/ARP Poisoning

NDP (IPv6 equivalent of ARP) Spoofing: Man in the Middle/NDP Spoofing

Port Stealing: Man in the Middle/Port Stealing

Rushing Attack: Man in the Middle/Rushing Attack

Layer 4 Attacks

DHCP Attack: Man in the Middle/DHCP

SSL Attacks: SSLStrip  · SSLSniff  · Certificates

Tools

Ettercap

Bettercap

Dsniff

SSLStrip

SSLSniff

Flags