Engadget

Man-In-The-Middle attack (MITM)

 tháng 10 17, 2009     Hacking     No comments   

Many a times a question would arises in your mind,

What is MITM ?

ok you wouldn't be able to understand it so lets take an example,fig1-w100-h100

An attacker puts up a fake bank website and entices user to that website. User types in his password, and the attacker in turn uses it to access the bank's real website. Done right, the user will never realize that he isn't at the bank's website. Then the attacker either disconnects the user and makes any fraudulent transactions he wants, or passes along the user's banking transactions while making his own transactions at the same time.

 

Here is what the Wikipedia says about MITM :-

In cryptography, the man-in-the-middle attack (often abbreviated MITM), or bucket-brigade attack, or sometimes Janus attack, is a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all messages going between the two victims and inject new ones, which is straightforward in many circumstances (for example, an attacker within reception range of an unencrypted Wi-Fi wireless access point, can insert himself as a man-in-the-middle).

A Man-in-the-middle attack can only be successful when the attacker can impersonate each endpoint to the satisfaction of the other. Most cryptographic protocols include some form of endpoint authentication specifically to prevent MITM attacks. For example, SSL authenticates the server using a mutually trusted certification authority.

 

Main_the_middle

MITM Techniques

Various defenses against MITM attacks use authentication techniques that are based on:

  • Public key infrastructures
  • Stronger mutual authentication

  • Secret keys (high information entropy secrets)

  • Passwords (low information entropy secrets)

  • Other criteria, such as voice recognition or other biometrics

  • Off-the-Record Messaging for instant messaging

  • Off-channel verification

  • Carry-forward verification

The integrity of public keys must generally be assured in some manner, but need not be secret. Passwords and shared secret keys have the additional secrecy requirement. Public keys can be verified by a Certificate Authority, whose public key is distributed through a secure channel (for example, with a web browser or OS installation). Public keys can also be verified by aweb of trust that distributes public keys through a secure channel (for example by face-to-face meetings).

 

See key agreement for a classification of protocols that use various forms of keys and passwords to prevent man-in-the-middle attacks.

MITM Tools For Hacking

  • dsniff - A tool for SSH and SSL MITM attacks monkey6.

  • Cain - A Windows GUI tool which can perform MITM attacks, along with sniffing and ARP poisoning
  • Ettercap - A tool for LAN based MITM attacks
  • Karma - A tool that uses 802.11 Evil Twin attacks to perform MITM attacks
  • AirJack - A tool that demonstrates 802.11 based MITM attacks
  • wsniff - A tool for 802.11 HTTP/HTTPS based MITM attacks
  • an additional card reader and a method to intercept key-presses on an Automated teller machine

 

 

The MITM attack could also be done over an https connection by using the same technique; the only difference consists in the establishment of two independent SSL sessions, one over each TCP connection. The browser sets a SSL connection with the attacker, and the attacker establishes another SSL connection with the web server. In general the browser warns the user that the digital certificate used is not valid, but the user may ignore the warning because he doesn’t understand the threat. In some specific contexts it’s possible that the warning doesn’t appear, as for example, when the Server certificate is compromised by the attacker or when the attacker certificate is signed by a trusted CA and the CN is the same of the original web site.

MITM is not only an attack technique, but is also usually used during the development step of a web application or is still used for Web Vulnerability assessments.

  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Gửi email bài đăng nàyBlogThis!Chia sẻ lên XChia sẻ lên Facebook
Bài đăng Mới hơn Bài đăng Cũ hơn Trang chủ

0 nhận xét:

Đăng nhận xét

Popular Posts

  • Proper use of English could get a virus past security
    “ Hackers evade most existing antivirus protection by hiding malicious code in texts, according to security researchers. ”
  • How to Rename Recycle Bin
    You can change the name of Recycle Bin Desktop Icon . 1-Click Start menu > Run > and type “regedit” (without quotes), to ru...
  • New BIOS Virus Which Can Make Your Anti-Virus Useless
    Hackers Have once again launched a Root kit Virus which loads directly into the BIOS memory of the computer and makes it prone . W...
  • Should You Use Hubitat to Automate Your Smarthome?
    The first step in building a smarthome is often choosing a hub, and there are many options. Hubitat is a unique cloud-independent hub. It...
  • 35+ Nokia Cheat Codes
    Nokia is a cell phone marketing company which is currently comes in world top rates mobile phones. Now its obvious that a company like No...
  • What’s the Difference Between Canon’s Regular and L-Series Lenses and Which Should You Buy
    Canon sells regular and L-series lenses (the "L" stands for luxury). While the lenses may have similar specs, you can usually exce...
  • Instructions to earn $ 10 / day to get Amazon Gift Card, Paypal
    You follow the steps below as well as for your Ref, please comment on how to make and receive money. The sponsor of this site is also Am...
  • Autodesk 3ds Max 2017 full + KeyGen - Professional 3D graphics
    Autodesk 3ds Max, formerly 3D Studio, then 3D Studio Max is a professional 3D graphics program for 3D animation, models, games and i...
  • INTRODUCTION AND GUIDANCE TO REGISTER VPS IN VULTR
    I. REGISTER VPS SERVER VULTR First we access the homepage of Vultr. Create a VPS account Here you need to enter email information to create ...
  • Download Adobe Photoshop PTS CS6 Full + Installation Guide
    As a designer, a photographer, or just a photo-editing enthusiast, no one is aware of adobe photoshop.  Adobe Photoshop CS6 was born long ag...

The Best Penlights for Pocket-Friendly Illumination

Your phone may have a built-in flashlight, but do you really feel comfortable propping your phone inside of your car's engine bay, or ag...

Được tạo bởi Blogger.

Copyright © Engadget | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates