
-: IP Spoofing :-

The term IP (Internet Protocol) address spoofing refers to the creation of IP packets with a forged (spoofed) source IP address with the purpose of concealing the identity of the sender or impersonating another computing system.
The main reason is security weakness in the TCP protocol known as sequence number prediction.
As you can see above, the first 12 bytes of the TCP packet, which contain port and sequencing information.
TCP sequence numbers can simply be thought of as 32-bit counters. They range from 0 to 4,294,967,295. Every byte of data exchanged across a TCP connection (along with certain flags) is sequenced. The sequence number field in the TCP header will contain the sequence number of the *first* byte of data in the TCP segment. The acknowledgement number field in the TCP header holds the value of next *expected* sequence number, and also acknowledges *all* data up through this ACK number minus one.
TCP packets can be manipulated using several packet crafting softwares available on the internet.
Spoofing can be implemented by different ways as given below -
Both types of spoofing are forms of a common security violation known as a Man In The Middle Attack. In these attacks, a malicious party intercepts a legitimate communication between two friendly parties. The malicious host then controls the flow of communication and can eliminate or alter the information sent by one of the original participants without the knowledge of either the original sender or the recipient. In this way, an attacker can fool a victim into disclosing confidential information by “spoofing” the identity of the original sender, who is presumably trusted by the recipient.
IP spoofing is almost always used in what is currently one of the most difficult attacks to defend against – Denial of Service attacks, or DoS.
| CounterMeasures |
-: IP Address :-Definition :- "An Internet Protocol (IP) address is a numerical identification (logical address) that is assigned to devices participating in a computer network utilizing the Internet Protocol for communication between its nodes". -- Wikipedia The Internet Protocol (IP) has two versions currently in use which are IPv4 and IPv6. This article represents to IPv4 version only. In general, an IP address is a 32-bit decimal number that is normally written as four numbers between 1 to 255 (8 bits or 1 byte each), each seperated from the other by a decimal point. This standard is known as "Dotted Decimal Notation". e.g.- 117.200.77.110 IP addresses are divided into number of ranges/classes as given in the table below-
e.g.- IP Address 192.168.24.114 belongs to Class 'C'. How to find out IP Address of your system ? 1) Connect to the Internet. 2) Launch MS-DOS Command Prompt. 3) Type "netstat -n", Press Enter. You will get the output similar to following- The IP Address shown in local address field denotes IP Address of your system. In this case it is 117.200.160.151 IP Address Formats :- Four different formats of IP Address along with example is as given below- 1) Domain Name System (DNS) : www.insecure.in 2) DWORD Format : 2928008962 3) Octal Format : 0256.0205.0337.002 4) Dotted Decimal Format : 174.133.223.2 Converting DNS IP Address into Normal IP Address :- You can easily get the IP Address of any domain by various methods such as WHOIS, Netstat, Ping, Traceroute, etc. Here I have used 'Ping' to get IP Address. 1) Connect to the Internet. 2) Launch MS-DOS Command Prompt. 3) Type "ping domainname", Press Enter. You will get the output similar to following- Here, IP Address for Domain "www.insecure.in" is "174.133.223.2" Thus by typing "http://www.insecure.in" OR "http://2928008962" OR "0256.0205.0337.02" OR "174.133.223.2" in your browser will take you to the same site.
|