From charlesreid1

Revision as of 06:04, 28 August 2015 by Admin (talk | contribs)

Wired Networks

Man in the Middle attacks on wired networks can happen with two different configurations, each requiring different strategies:

  • Network Neighbor setup
  • Network Tap setup

Network Neighbor

See Man in the Middle/Wired/ARP Poisoning page

The Network Neighbor setup involves an attacker and a sheep that are both connected directly to a router or network switch:

+----[Target computer]
|
|      +---[Attack computer]
|      |
|      |
[Router]

This configuration requires a man in the middle attack to proceed by ARP spoofing, in which the attacker changes the router/network switch table that maps MAC addresses to IP addresses. This allows the attacker to send/receive traffic, and pass it through to another computer on the network (the target).

Network Tap

See Man in the Middle/Wired/Network Tap page

In the network tap setup, the attacker physically sits between the sheep and the network router or network switch:

    +--------[Target computer]
    |
    |
[ Attack computer ]
    |
    |
[Router]


Tools

Ettercap - for setting up and executing a man in the middle attack via ARP cache poisoning (among other methods)

Wireshark - for viewing packets and plaintext HTTP traffic during a man in the middle session

Driftnet - for viewing images during a man in the middle session