امن شبكات 1.2

Certified Network Defender (CND)

Module 01: Network Attack and Defense Strategies

Building A Culture Of Security
  • Copyright © by EC-Council. All Rights Reserved. Reproduction is Strictly Prohibited.


SQL Injection Attack

Definition

SQL injection attacks use a series of malicious SQL queries to directly manipulate a database. It allows an attacker to use a vulnerable web application to bypass normal security measures and obtain direct access to valuable data.

Execution Methods

  • SQL injection attacks can often be executed from:

    • The address bar of a browser

    • Within application fields

    • Through queries and searches

Conditions for Attack

This attack is possible only when:

  • The application executes dynamic SQL statements and stored procedures with arguments based on user input.

Example of Attack Execution
  1. User Input: Attackers may manipulate a user login by crafting input that always returns true.

  2. SQL Code: An example code snippet:

   SqlDataAdapter my_query = new SqlDataAdapter("SELECT account_balance FROM userdata WHERE username = ?", the_connection);
  • When this username is sent to the server, it allows access to the database and the ability to execute the query.


SQL Injection Attack Example

Detailed Example

For instance, a basic SQL query could be:

SELECT * FROM tablename WHERE UserID= 2302
  • Malicious Injection: An attacker could modify it to:

SELECT * FROM tablename WHERE UserID= 2302 OR 1=1
  • Reasoning: The expression "OR 1=1" evaluates to true, often allowing attackers to enumerate all user IDs from the database.

Effects of SQL Injection Attacks

These attacks can enable attackers to:

  • Log into the application without providing valid credentials.

  • Perform unauthorized queries against data that should be restricted.

  • Modify database content or even delete the database completely.

  • Gain access to other databases via established trust relationships among the web application components.


Cross-site Scripting (XSS) Attack

Definition

Cross-site scripting (XSS) attacks exploit vulnerabilities in dynamically generated web pages, enabling attackers to inject client-side scripts into web pages viewed by other users.

Mechanism

XSS occurs when unvalidated input data is included in dynamic content sent for rendering in the user's web browser.

Example Attack Flow
  1. Normal Request: A typical user requests a URL, such as http://example.com/jason/jason_file.html.

  2. Server Response: Comes with a 404 error code.

  3. Injection Point: Attacker injects malicious code like:

<script>alert("WARNING: The application has encountered an error");</script>
  1. This misconfiguration allows the execution of the script on the victim's system.

Example Code in Response
<body>
   Response.Redirect("welcome.aspx?Email=" + Signin.Text);
</body>
  • Security Compromised: The application fails to validate the injected data securely, facilitating XSS.


Parameter Tampering Attack

Definition

A web parameter tampering attack involves the manipulation of parameters exchanged between client and server to modify application data, such as user credentials and permissions, or product pricing.

Mechanisms and Vulnerabilities

  • This type of attack exploits the vulnerabilities in integrity and logic validation mechanisms, which can result in other attacks like XSS, SQL injection, etc.

URL Manipulation Example

Before Tampering
http://www.example.com/cust.asp?profile=21&debit=2500
After Tampering
http://www.example.com/cust.asp?profile=82&debit=1500
  • Other parameters, such as status can be modified:

http://www.example.com/stat.asp?pg=147&status-delete
  • This can allow an attacker to delete a page from the server.


Directory Traversal Attack

Definition

Directory traversal enables attackers to access restricted directories including application source code, configuration files, and critical system files, and execute commands outside the webserver's root directory.

Mechanism

URL Manipulation Technique

Attackers manipulate variables referencing files with "dot-dot-slash (../)" sequences and its variations.

Example Requests
  1. http://www.example.com/process.aspx=../../../../some_dir/some_file

  2. http://www.example.com/GET/process.php./../../etc/passwd

Result of an Attack
  • Server Response: Considerable sensitive files can be exposed:

root:a98b24a1d3e8:0:1:System Operator:/:/bin/ksh
daemon:*:1:1::/tmp:
  • Vulnerabilities in Code: Poorly validated input can lead to attacks:

String filename = Request.QueryString["filename"]; 
if (filename = null)

Cross-site Request Forgery (CSRF) Attack

Definition

CSRF attacks exploit vulnerabilities that enable an attacker to force an unsuspecting user's browser to send malicious requests.

Mechanism

  • The victim is logged into a trusted site and simultaneously visits a malicious site that injects an HTTP request into the victim's session, compromising its integrity.

Attack Flow
  1. Login Sequence: User logs into the trusted site, and the session identifier is stored in a cookie.

  2. Visit to Malicious Site: User gets redirected to a malicious site where a forged request is sent from the user’s browser utilizing the stored session cookie.


Application-level DoS Attack

Definition

Attackers exhaust available server resources by sending numerous resource-intensive requests.

Characteristics

  • Requests can involve retrieving large files or executing computationally expensive operations on the backend of database servers.

  • Application-level DoS attacks mimic the same request syntax and network-level traffic characteristics of legitimate clients, thus evading standard detection efforts.

Targets

  • CPU, Memory, and Sockets

  • Disk Bandwidth

  • Database Bandwidth

  • Worker Processes

Why Vulnerable to DoS?

  • Reasonable Use Expectations

  • Bottlenecks in the Application Environment

  • Implementation Flaws

  • Poor Data Validation


Session Hijacking Attack

Definition

Session hijacking is when an attacker takes over a valid TCP communication session between two computers.

Mechanism

  • Attackers can sniff traffic from established TCP sessions and perform identity theft, information theft, and fraud.

  • The attacker steals a valid session ID, authentication themselves with the server.


OWASP Top 10 Vulnerabilities

Overview of OWASP

OWASP (Open Web Application Security Project) is a non-profit organization enhancing software security; it defines critical vulnerabilities in web applications such as:

  1. Broken Access Control

  2. Cryptographic Failures

  3. Injection

  4. Insecure Design

  5. Security Misconfiguration

  6. Vulnerable and Outdated Components

  7. Identification and Authentication Failures

  8. Software and Data Integrity Failures

  9. Security Logging and Monitoring Failures

  10. Server-Side Request Forgery (SSRF)

  • Source: https://owasp.org


Social Engineering Attacks

Definition

Social engineering is the art of convincing individuals to reveal confidential information.

Techniques of Social Engineering

Impersonation
  • Attackers pretend to be someone legitimate, either in person or through communication mediums (e.g., phone, email).

Example Scenarios
  1. As a Legitimate User:

    • An attacker claims: "Hi! This is John from the finance department. I have forgotten my password. Can I get it?"

  2. Pretending to be a VIP:

    • Example: "Hi! This is Kevin, CFO Secretary. I'm working on an urgent project and lost my system's password. Can you help me out?"

  3. Technical Support Call:

    • Example: "Sir, this is Mathew from Technical Support, X company. We had a system crash, can you provide your ID and password?"


Eavesdropping and Shoulder Surfing

Definitions

Eavesdropping

Eavesdropping is the act of unauthorized listening to conversations or reading messages.

Shoulder Surfing

Shoulder surfing involves direct observation, often by peeking over someone's shoulder to gather sensitive information like passwords, PINs, or account numbers.


Email Attacks

Types of Email Attacks

  1. Malicious Email Attachments: Attachments can deliver malware (viruses, worms, trojans).

    • Example Email: "Please run attached file to regain account access."

  2. Malicious User Redirection: Emails containing links redirect victims to malware-hosting sites.

  3. Phishing Attacks: Attackers send deceptive emails asking for personal/financial information.

    • Common indicators: Generic greetings, spelling mistakes, sense of urgency, and requests for personal details.

  4. Spamming: Unsolicited advertisements with unreliable content. Spam persists due to people responding to them.

  5. Email Bombing: Sending large volumes of emails to block legitimate communications.


Mobile Device-Specific Attack Techniques

Rooting and Jailbreaking

  • Rooting (Android): Attaining privileged control within Android’s subsystem, often through exploiting vulnerabilities.

  • Jailbreaking (iOS): Installing modified kernel patches to run unauthorized applications.

Mobile Spamming

  • Unsolicited messages sent to mobile devices, often containing advertisements or malicious links that can lead to information theft.

SMS Phishing Attack (SMiShing)

  • Targeting users via deceptive SMS messages requesting personal information or redirecting them to phishing sites.


Cloud-Specific Attack Techniques

Cloud Threats

Cloud computing can face threats such as data breaches, shared technology issues, and insecure interfaces.

OWASP Top 10 Cloud Security Risks
  1. Accountability and Data Ownership

  2. User Identity Federation

  3. Regulatory Compliance

  4. Business Continuity and Resiliency

  5. User Privacy and Secondary Usage of Data

  6. Service and Data Integration

  7. Multi-tenancy and Physical Security

  8. Incident Analysis and Forensic Support

  9. Infrastructure Security

  10. Non-Production Environment Exposure


Wireless Network-Specific Attack Techniques

Types of Attacks

  1. War Driving: Detecting open networks using Wi-Fi-enabled laptops.

  2. Rogue Access Point Attack: Unauthorized access points that hijack legitimate user connections.

  3. Denial-of-Service (DoS): Disrupting wireless connections using de-authentication commands.

Additional Techniques

  • WPA/PSK Cracking, Man-in-the-Middle attacks, MAC Spoofing, and Jamming Signal Attacks.


Supply Chain Attack Techniques

Definition and Exploitation

A supply chain attack aims to compromise security by exploiting vulnerabilities across the supply chain, impacted by both hardware and software.

Categories of Attack

  1. Hardware-based: Tampering with hardware components like malicious USB devices.

  2. Software-based: Injecting malware during software updates.

  3. Firmware-based: Targeting software embedded in hardware.

  4. Malware Distribution: Attacks on legitimate software distribution channels.


Hacking Methodologies and Frameworks

CEH Hacking Methodology

  1. Reconnaissance

  2. Scanning

  3. Gaining Access

  4. Maintaining Access

  5. Clearing Tracks

Lockheed Martin's Cyber Kill Chain

  1. Reconnaissance

  2. Delivery

  3. Exploitation

  4. Installation

  5. Command and Control

  6. Actions on Objectives

MITRE ATT&CK Framework

  • A globally accessible knowledge base focusing on tactics and techniques related to real-world observations.


Network Defense Goals, Benefits, and Challenges

Goals of Network Defense

The ultimate goal is to protect an organization's information, systems, and infrastructure from unauthorized access, misuse, and degradation.
After implementing Information Assurance (IA) principles, organizations can rely on a defense-in-depth strategy.

Benefits of Network Defense

  • Protecting information assets

  • Complying with regulations

  • Ensuring secure communication

  • Reducing risk of attacks

  • Gaining a competitive advantage

Challenges in Network Defense

  • Increasing complexity of networks leading to security vulnerabilities.

  • Sophisticated emerging threats.

  • Shortage of skilled network security professionals.


Continual/Adaptive Security Strategy

Definition and Implementation

Adopting a continual/adaptive security strategy involves:

  1. Protect: Countermeasures for eliminating vulnerabilities.

  2. Detect: Continuous monitoring for abnormalities.

  3. Respond: Actions taken to mitigate attacks.

  4. Predict: Identifying potential attack vectors before they can occur.


Defense-in-Depth Security Strategy

Overview

Defense-in-depth comprises multi-layered security measures to protect organizational assets.

  • Layers Include:

    1. Physical

    2. Perimeter

    3. Internal Network

    4. Host/Application

    5. Data

Implementation Factors
  1. Appropriate selection of technology (e.g., firewalls, IDS).

  2. Proper procedures (e.g., incident response protocols).

  3. The necessary skill of personnel to implement strategies.


Module Summary

  • Threats exploit paths for unauthorized access.

  • Attackers employ methodologies for successful execution of attacks.

  • Computer network defense encompasses protective measures to defend against degradation and disruption.

  • Engagement of blue teams is crucial for developing effective defense strategies.

  • Continuous improvement and a multi-layered approach are vital for security.