기본 콘텐츠로 건너뛰기

ICMP Fragmetation 공격

Fragmented ICMP

While they can occur, fragmented ICMP packets are usually not seen, except in conditions which could be labeled as “malicious”. It is advised to drop these packets completely, even before further analysing them using regular access lists.
Example access-lists [back]

Cisco IOS

Access-list 101 (to be applied to the external interface)
access-list 101 deny icmp any any fragments
access-list 101 permit icmp any any echo-reply
access-list 101 permit icmp any any time-exceeded
access-list 101 permit icmp any any packet-too-big
access-list 101 deny icmp any any

Access-list 102 (to be applied to the internal interface)
access-list 102 deny icmp any any fragments
access-list 102 permit icmp any any echo-request
access-list 102 permit icmp any any time-exceeded
access-list 102 permit icmp any any packet-too-big
access-list 102 deny icmp any any

Linux iptables

iptables -A INPUT -p icmp --fragment -j DROP
iptables -A INPUT -p icmp --icmp-type echo-reply -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type echo-request -j ACCEPT
iptables -A INPUT -p icmp --icmp-type time-exceeded -j ACCEPT

iptables -A INPUT -p icmp --icmp-type fragmentation-needed -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type time-exceeded -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type fragmentation -needed -j ACCEPT
iptables -A INPUT -p ICMP -j DROP
iptables -A OUTPUT -p ICMP -j DROP

공격 및 방어
http://light99.egloos.com/5220504

https://www.linux.co.kr/security/certcc/IP%20Fragmentation.htm

http://devdev.tistory.com/63

댓글

이 블로그의 인기 게시물

보안 공부 링크

SSLsplit - SSL/TLS기반의 네트워크 포렌식 및 침투테스트(중간자공격) 도구 http://www.roe.ch/SSLsplit 가상화 서버운영 및 구축을 위한 Xenserver가 오픈소스로 공개 http://www.xenserver.org/ Python과 Fabric를 사용한 SSH 봇넷 C&C 구축 예제 http://raidersec.blogspot.kr/2013/07/building-ssh-botnet-c-using-python-and.html 파워쉘을 이용한 비밀번호 정보 획득 http://www.obscuresecurity.blogspot.kr/2013/07/get-gpppassword.html niktoHelper - Nmap의 Grepable형식을 Nikito와 연동하기 위한 파이썬 스크립트 http://milo2012.wordpress.com/2013/07/07/niktohelper-bridge-between-nmap-grepable-output-and-nikto/ 루비를 통한 심도있는 XSS 방어 방법 http://homakov.blogspot.com.es/2013/07/xss-defense-in-depth-with-rackrails-demo.html IT관련 E-Book 모음 http://www.cyberhades.com/2013/07/04/unos-libritos-tecnicos-para-el-veranito JJEncode 스크립트 분석 http://www.kahusecurity.com/2013/jjencode-script-leads-to-drive-by/ 웹브라우저 호환성 검증 및 분석결과 제공 http://www.modern.ie/ko-kr/ http://browsershots.org/ html 색상 선택 도구 https://kuler.adobe.com/create/color-wheel/ Windows 메모리 보호 메커니즘 http://resources.infosecinstitute.com/window...

dns2proxy 해킹툴

dns2proxy Offensive DNS server This tools offer a different features for post-explotation once you change the DNS server to a Victim. <Referer to help (-h) to new params options> Feature 1 Traditional DNS Spoof adding to the response the original IP address. Using spoof.cfg file: hostname ip.ip.ip.ip root@kali:~/dns2proxy# echo " www.s21sec.com  1.1.1.1" > spoof.cfg // launch in another terminal dns2proxy.py root@kali:~/dns2proxy# nslookup  www.s21sec.com  127.0.0.1 Server: 127.0.0.1 Address: 127.0.0.1#53 Name:  www.s21sec.com Address: 1.1.1.1 Name:  www.s21sec.com Address: 88.84.64.30 or you can use domains.cfg file to spoof all host of a same domain: root@kali:~/demoBH/dns2proxy# cat dominios.cfg .domain.com 192.168.1.1 root@kali:~/demoBH/dns2proxy# nslookup aaaa.domain.com 127.0.0.1 Server: 127.0.0.1 Address: 127.0.0.1#53 Name: aaaa.domain.com Address: 192.168.1.1 Hostnames at nospoof.cfg will no be spoofed. Featu...

어셈블리어(Assembly) 기초

0x01.  어셈블리 언어란 ? &  배우는 목적 CPU  에는 해당 프로세서에 명령을 내리기 위해 고유의 명령어 세트가 마련되어 있는데 이  명령어 세트를 기계어라고 한다 .  이 기계어는 숫자들의 규칙조합임으로 프로그래밍에 상당 히 난해하다 .  그래서 이 기계 명령어를 좀더 이해하기 쉬운 기호 코드로 나타낸것 ( 기계어와  1:1 로 대응된 명령을 기술하는 언어 ) 이 어셈블리어이다 .  어셈블리 언어는 그 코드가 어떤  일을 할지를 추상적이 아닌 ,  직접적으로 보여준다 .  논리상의 오류나 ,  수행 속도 ,  수행 과정 에 대해 명확히 해준다는 점에서 직관적인 언어이다 .  어셈블리 언어를 사용하면 메모리에 대한 이해도도 높아진다 .  어셈블리를 익히고 ,  배우는데 있어서는 여러 가지 목적이 있을 수 있다 .  컴퓨터 시스템 & 구조를 좀 더 깊게 이해하고 ,  메모리상의 데이터나  I/O 기기를 직접 액 세스 하는등의 고급언어에서는 할 수 없는 조작을위해서이다 .  프로그램의 최적화 및 리버 스 엔지니어링을 위해서도 필요하다 . + 2 줄 요약  + -  어셈블리 언어는 기계어와  1:1  대응을 하는 언어이다 . -  어셈블리 언어를 배우면 시스템을 이해하는데 도움이 된다 . 0x02.  어셈블리를 위한 기본 지식 (1)  기본적인 하드웨어 1) CPU -  메모리에 있는 내용을 읽고 ,  쓰고 데이터를 메모리와 각 레지스터로 보낸다 . 프로그램의 명령을 해석하고 실행한다 . 하나의 프로세서는  12~14 개의 레지스터를 가 지고 있으며 , CPU 의 연산 ,  논리 장치는 숫자와 기호에 관한 연산자를...