+ - 0:00:00
Notes for current slide
Notes for next slide

MitM

Man-in-the-Middle

https://dumpco.re/slides/mitm

Introduction

  • Magnus Klaaborg Stubman
    • Security Advisor @ Improsec, OSCE, OSCP
      • Red Teaming
      • Secure Development Training
      • Application Security
      • Source Code Review
      • Linux Security
    • @: mks@improsec.com
    • T: (+45) 31 23 01 58

Agenda

- Rogue DHCP "DHCP Spoofing"

- Rogue DHCPv6 on IPv4 networks

Rogue DHCP

Legitimate DHCP

Malicious DHCP

Malicious DHCP

Malicious DHCP

Malicious DHCP

Malicious DHCP

Rogue DHCPv6 on IPv4 networks

By default

Full packet capture at

http://dumpco.re/lab/mitm6.pcapng

Fuzzing

slides: http://dumpco.re/fuzz

Suggestions

- Fuzz something, e.g. UPX with AFL

- Analyze packet captures

- Try mitm6 or other MitM techniques

Tools

- VirtualBox: virtualbox.org/wiki/Downloads

- Kali VM: www.kali.org/downloads/

- mitm6: https://github.com/fox-it/mitm6

ty

@magnusstubman

Introduction

  • Magnus Klaaborg Stubman
    • Security Advisor @ Improsec, OSCE, OSCP
      • Red Teaming
      • Secure Development Training
      • Application Security
      • Source Code Review
      • Linux Security
    • @: mks@improsec.com
    • T: (+45) 31 23 01 58
Paused

Help

Keyboard shortcuts

, , Pg Up, k Go to previous slide
, , Pg Dn, Space, j Go to next slide
Home Go to first slide
End Go to last slide
Number + Return Go to specific slide
b / m / f Toggle blackout / mirrored / fullscreen mode
c Clone slideshow
p Toggle presenter mode
t Restart the presentation timer
?, h Toggle this help
Esc Back to slideshow