Re: tcp/routing question...

From: Lai Zit Seng (lzs_at_pobox.com)
Date: 06/08/05

  • Next message: dfghd tyuthjg: "WebServer : problem found"
    Date: Wed, 08 Jun 2005 09:12:46 +0800
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    Joel Jaeggli wrote:
    > On Wed, 8 Jun 2005, Lai Zit Seng wrote:
    >
    >> On Tue, 7 Jun 2005, Scot L. Harris wrote:
    >>
    >>> The difficulty is in getting a system inserted into such a position. It
    >>> typically requires physically inserting a system in the path unless the
    >>> attacker is able to mess with the end systems proxy settings and
    >>> redirect things that way.
    >>
    >>
    >> In practice, there are many ways to do this, so it's actually not
    >> terribly difficult. E.g. one could subvert the DNS so that the client
    >> unwittingly connects to the wrong server.
    >
    >
    > route injection, address space hijack, arp spoofing (ie masquerding as
    > the gateway or the host) on either ends edge network, etc...

    Heh... yes those are many more excellent examples. Also consider if your
    ISP is the bad guy, or your ISP themselves got hacked... so it becomes
    even more trivial to do MITM. The important thing to know is that these
    are not difficult to do, so the question isn't so much how to do MITM
    attack... it can be done... we have to deal with it :)

    Regards,

    .lzs

    --
    http://zitseng.com/
    >> Regards
    >>
    >> .lzs
    >> -- 
    >> http://zitseng.com/
    >>
    >>
    > 
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: dfghd tyuthjg: "WebServer : problem found"

    Relevant Pages

    • Re: DNS resolution
      ... "xpto.company.com" on My ISP maps to 213.142.1.27 ... Can anyone explain me step by step how it's done in a win2000 DNS ... Best regards, ...
      (microsoft.public.win2000.dns)
    • Re: New SMTP Address
      ... And how do i configure my DNS? ... that points to my ISP? ... > You create a recipient policy that defines the new SMTP ...
      (microsoft.public.exchange2000.general)
    • Re: force OSX to use other DNS
      ... But I've just found out that the site wasn't unreachable because of the dns for once. ... But Next time I've got to gap the crappy DNS my ISP offers, ... Best Regards ...
      (comp.sys.mac.misc)
    • Re: Sendmail authentication issue or spam?
      ... issue..however as regards my sending mail...I misconfigured my ... sendmail.mc and the client-info file.. ... Did you set the smart host in sendmail.mc or do you use a ... You should get your ISP to talk to Spamhaus, tell them what they did to ...
      (Fedora)
    • Re: SMTP Email collection over ADSL
      ... Regards ... >> I found out after calling the ISP, that they hadn't got around to ... >> set mail to collect via DNS, ... >> Nick Hill ...
      (microsoft.public.backoffice.smallbiz2000)