Network Manipulation

Table 3-7 shows the summary information for the network manipulation attack.

Table 3-7. Network Manipulation

Attack name

Network manipulation

Class/subclass

Manipulate

Sample implementations

Fragroute

Prerequisites

Variable

Pertinent vulnerability

Software

Typical use

Bypass security technology

Attack result

Increased access

Likely follow-up attack

Read and composite

OSI layers

34

Detection

IDS, routers

Protection

Firewall/application security/cryptography

Detection difficulty

2

Ease of use

3

Frequency

2

Impact

3

Overall rating

26

The most common network manipulation attack is IP fragmentation. Here the attacker intentionally fragments traffic in an effort to bypass a security control, which could be network based (IDS or firewall) or application based. One tool used to launch an IP fragmentation attack is called Fragroute. More information about Fragroute is available at http://monkey.org/~dugsong/fragroute/. For details on the ways fragmentation can be used to bypass security devices, take a look at the paper titled "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection" at http://www.insecure.org/stf/secnet ids/secnet ids.html.

In addition to IP fragmentation, the attacker can execute a source route attack. Source routing allows the attacker to pick the path of the attack through the network. Source routing has almost no legitimate use and is turned off by default on most routers.

IP and Transmission Control Protocol (TCP) are complex protocols. User Datagram Protocol (UDP) is less so. Still, all of these protocols leave a fair bit of room for creative attackers to do things the protocols were not designed to do. Although not exclusively intended for attacks, Dan Kaminsky's Paketto suite of tools shows what can be done with TCP/IP given sufficient motivation and free time: http://www.doxpara.com/read.php/code/paketto.html.

Continue reading here: Table 38 Buffer Overflow

Was this article helpful?

+2 0