امن شبكات 1.2
Certified Network Defender (CND)
Module 01: Network Attack and Defense Strategies
Building A Culture Of Security
Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.
SQL Injection Attack
Definition
SQL injection attacks use a series of malicious SQL queries to directly manipulate a database. It allows an attacker to use a vulnerable web application to bypass normal security measures and obtain direct access to valuable data.
Execution Methods
SQL injection attacks can often be executed from:
The address bar of a browser
Within application fields
Through queries and searches
Conditions for Attack
This attack is possible only when:
The application executes dynamic SQL statements and stored procedures with arguments based on user input.
Example of Attack Execution
User Input: Attackers may manipulate a user login by crafting input that always returns true.
SQL Code: An example code snippet:
SqlDataAdapter my_query = new SqlDataAdapter("SELECT account_balance FROM userdata WHERE username = ?", the_connection);
When this username is sent to the server, it allows access to the database and the ability to execute the query.
SQL Injection Attack Example
Detailed Example
For instance, a basic SQL query could be:
SELECT * FROM tablename WHERE UserID= 2302
Malicious Injection: An attacker could modify it to:
SELECT * FROM tablename WHERE UserID= 2302 OR 1=1
Reasoning: The expression "OR 1=1" evaluates to true, often allowing attackers to enumerate all user IDs from the database.
Effects of SQL Injection Attacks
These attacks can enable attackers to:
Log into the application without providing valid credentials.
Perform unauthorized queries against data that should be restricted.
Modify database content or even delete the database completely.
Gain access to other databases via established trust relationships among the web application components.
Cross-site Scripting (XSS) Attack
Definition
Cross-site scripting (XSS) attacks exploit vulnerabilities in dynamically generated web pages, enabling attackers to inject client-side scripts into web pages viewed by other users.
Mechanism
XSS occurs when unvalidated input data is included in dynamic content sent for rendering in the user's web browser.
Example Attack Flow
Normal Request: A typical user requests a URL, such as
http://example.com/jason/jason_file.html.Server Response: Comes with a 404 error code.
Injection Point: Attacker injects malicious code like:
<script>alert("WARNING: The application has encountered an error");</script>
This misconfiguration allows the execution of the script on the victim's system.
Example Code in Response
<body>
Response.Redirect("welcome.aspx?Email=" + Signin.Text);
</body>
Security Compromised: The application fails to validate the injected data securely, facilitating XSS.
Parameter Tampering Attack
Definition
A web parameter tampering attack involves the manipulation of parameters exchanged between client and server to modify application data, such as user credentials and permissions, or product pricing.
Mechanisms and Vulnerabilities
This type of attack exploits the vulnerabilities in integrity and logic validation mechanisms, which can result in other attacks like XSS, SQL injection, etc.
URL Manipulation Example
Before Tampering
http://www.example.com/cust.asp?profile=21&debit=2500
After Tampering
http://www.example.com/cust.asp?profile=82&debit=1500
Other parameters, such as
statuscan be modified:
http://www.example.com/stat.asp?pg=147&status-delete
This can allow an attacker to delete a page from the server.
Directory Traversal Attack
Definition
Directory traversal enables attackers to access restricted directories including application source code, configuration files, and critical system files, and execute commands outside the webserver's root directory.
Mechanism
URL Manipulation Technique
Attackers manipulate variables referencing files with "dot-dot-slash (../)" sequences and its variations.
Example Requests
http://www.example.com/process.aspx=../../../../some_dir/some_filehttp://www.example.com/GET/process.php./../../etc/passwd
Result of an Attack
Server Response: Considerable sensitive files can be exposed:
root:a98b24a1d3e8:0:1:System Operator:/:/bin/ksh
daemon:*:1:1::/tmp:
Vulnerabilities in Code: Poorly validated input can lead to attacks:
String filename = Request.QueryString["filename"];
if (filename = null)
Cross-site Request Forgery (CSRF) Attack
Definition
CSRF attacks exploit vulnerabilities that enable an attacker to force an unsuspecting user's browser to send malicious requests.
Mechanism
The victim is logged into a trusted site and simultaneously visits a malicious site that injects an HTTP request into the victim's session, compromising its integrity.
Attack Flow
Login Sequence: User logs into the trusted site, and the session identifier is stored in a cookie.
Visit to Malicious Site: User gets redirected to a malicious site where a forged request is sent from the user’s browser utilizing the stored session cookie.
Application-level DoS Attack
Definition
Attackers exhaust available server resources by sending numerous resource-intensive requests.
Characteristics
Requests can involve retrieving large files or executing computationally expensive operations on the backend of database servers.
Application-level DoS attacks mimic the same request syntax and network-level traffic characteristics of legitimate clients, thus evading standard detection efforts.
Targets
CPU, Memory, and Sockets
Disk Bandwidth
Database Bandwidth
Worker Processes
Why Vulnerable to DoS?
Reasonable Use Expectations
Bottlenecks in the Application Environment
Implementation Flaws
Poor Data Validation
Session Hijacking Attack
Definition
Session hijacking is when an attacker takes over a valid TCP communication session between two computers.
Mechanism
Attackers can sniff traffic from established TCP sessions and perform identity theft, information theft, and fraud.
The attacker steals a valid session ID, authentication themselves with the server.
OWASP Top 10 Vulnerabilities
Overview of OWASP
OWASP (Open Web Application Security Project) is a non-profit organization enhancing software security; it defines critical vulnerabilities in web applications such as:
Broken Access Control
Cryptographic Failures
Injection
Insecure Design
Security Misconfiguration
Vulnerable and Outdated Components
Identification and Authentication Failures
Software and Data Integrity Failures
Security Logging and Monitoring Failures
Server-Side Request Forgery (SSRF)
Source: https://owasp.org
Social Engineering Attacks
Definition
Social engineering is the art of convincing individuals to reveal confidential information.
Techniques of Social Engineering
Impersonation
Attackers pretend to be someone legitimate, either in person or through communication mediums (e.g., phone, email).
Example Scenarios
As a Legitimate User:
An attacker claims: "Hi! This is John from the finance department. I have forgotten my password. Can I get it?"
Pretending to be a VIP:
Example: "Hi! This is Kevin, CFO Secretary. I'm working on an urgent project and lost my system's password. Can you help me out?"
Technical Support Call:
Example: "Sir, this is Mathew from Technical Support, X company. We had a system crash, can you provide your ID and password?"
Eavesdropping and Shoulder Surfing
Definitions
Eavesdropping
Eavesdropping is the act of unauthorized listening to conversations or reading messages.
Shoulder Surfing
Shoulder surfing involves direct observation, often by peeking over someone's shoulder to gather sensitive information like passwords, PINs, or account numbers.
Email Attacks
Types of Email Attacks
Malicious Email Attachments: Attachments can deliver malware (viruses, worms, trojans).
Example Email: "Please run attached file to regain account access."
Malicious User Redirection: Emails containing links redirect victims to malware-hosting sites.
Phishing Attacks: Attackers send deceptive emails asking for personal/financial information.
Common indicators: Generic greetings, spelling mistakes, sense of urgency, and requests for personal details.
Spamming: Unsolicited advertisements with unreliable content. Spam persists due to people responding to them.
Email Bombing: Sending large volumes of emails to block legitimate communications.
Mobile Device-Specific Attack Techniques
Rooting and Jailbreaking
Rooting (Android): Attaining privileged control within Android’s subsystem, often through exploiting vulnerabilities.
Jailbreaking (iOS): Installing modified kernel patches to run unauthorized applications.
Mobile Spamming
Unsolicited messages sent to mobile devices, often containing advertisements or malicious links that can lead to information theft.
SMS Phishing Attack (SMiShing)
Targeting users via deceptive SMS messages requesting personal information or redirecting them to phishing sites.
Cloud-Specific Attack Techniques
Cloud Threats
Cloud computing can face threats such as data breaches, shared technology issues, and insecure interfaces.
OWASP Top 10 Cloud Security Risks
Accountability and Data Ownership
User Identity Federation
Regulatory Compliance
Business Continuity and Resiliency
User Privacy and Secondary Usage of Data
Service and Data Integration
Multi-tenancy and Physical Security
Incident Analysis and Forensic Support
Infrastructure Security
Non-Production Environment Exposure
Wireless Network-Specific Attack Techniques
Types of Attacks
War Driving: Detecting open networks using Wi-Fi-enabled laptops.
Rogue Access Point Attack: Unauthorized access points that hijack legitimate user connections.
Denial-of-Service (DoS): Disrupting wireless connections using de-authentication commands.
Additional Techniques
WPA/PSK Cracking, Man-in-the-Middle attacks, MAC Spoofing, and Jamming Signal Attacks.
Supply Chain Attack Techniques
Definition and Exploitation
A supply chain attack aims to compromise security by exploiting vulnerabilities across the supply chain, impacted by both hardware and software.
Categories of Attack
Hardware-based: Tampering with hardware components like malicious USB devices.
Software-based: Injecting malware during software updates.
Firmware-based: Targeting software embedded in hardware.
Malware Distribution: Attacks on legitimate software distribution channels.
Hacking Methodologies and Frameworks
CEH Hacking Methodology
Reconnaissance
Scanning
Gaining Access
Maintaining Access
Clearing Tracks
Lockheed Martin's Cyber Kill Chain
Reconnaissance
Delivery
Exploitation
Installation
Command and Control
Actions on Objectives
MITRE ATT&CK Framework
A globally accessible knowledge base focusing on tactics and techniques related to real-world observations.
Network Defense Goals, Benefits, and Challenges
Goals of Network Defense
The ultimate goal is to protect an organization's information, systems, and infrastructure from unauthorized access, misuse, and degradation.
After implementing Information Assurance (IA) principles, organizations can rely on a defense-in-depth strategy.
Benefits of Network Defense
Protecting information assets
Complying with regulations
Ensuring secure communication
Reducing risk of attacks
Gaining a competitive advantage
Challenges in Network Defense
Increasing complexity of networks leading to security vulnerabilities.
Sophisticated emerging threats.
Shortage of skilled network security professionals.
Continual/Adaptive Security Strategy
Definition and Implementation
Adopting a continual/adaptive security strategy involves:
Protect: Countermeasures for eliminating vulnerabilities.
Detect: Continuous monitoring for abnormalities.
Respond: Actions taken to mitigate attacks.
Predict: Identifying potential attack vectors before they can occur.
Defense-in-Depth Security Strategy
Overview
Defense-in-depth comprises multi-layered security measures to protect organizational assets.
Layers Include:
Physical
Perimeter
Internal Network
Host/Application
Data
Implementation Factors
Appropriate selection of technology (e.g., firewalls, IDS).
Proper procedures (e.g., incident response protocols).
The necessary skill of personnel to implement strategies.
Module Summary
Threats exploit paths for unauthorized access.
Attackers employ methodologies for successful execution of attacks.
Computer network defense encompasses protective measures to defend against degradation and disruption.
Engagement of blue teams is crucial for developing effective defense strategies.
Continuous improvement and a multi-layered approach are vital for security.