Network Security: A Practical Approach

Chapter 6: Spoofing

In This Chapter

  • TCP spoofing

  • DNS spoofing

  • IP (and e-mail) spoofing

  • Web spoofing

6.0 Introduction

The term spoofing applies to actions that make an electronic transmission appear to originate from somewhere that it does not. Spoofing can be used to steal sensitive information, such as the social engineering attacks based on e-mail and Web spoofs (introduced in Chapter 3). By falsifying source IP addresses, a cracker can initiate a denial of service attack. In this chapter, we ll look at what can be spoofed and how you can detect when something has been faked.

Reality Check

It s impossible to stop a cracker from mounting a spoofed attack because the cracker falsifies something and then launches it at your network. You d need contact with the cracker before the phony packet e-mail URL was generated to prevent such an attack. The best you can do is detect the spoofed attack and discard spoofed items.

6.1 TCP Spoofing

TCP spoofing is a technique for convincing the recipient of a TCP segment that the message is coming from a source other than the attacker. Often known as the man in the middle attack, it can be used to disseminate false information on which the recipient might act or to deliver pay-loads (attachments) that contain malware.

TCP spoofing takes advantage of the way in which the TCP processes on source and destination machines establish and maintain a connection: the three-way handshake. In Figure 6.1 you...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: E-Mail Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.