Network Vulnerabilities and Attacks · Vulnerabilidades e Ataques de Rede
| English | Português |
|---|---|
| ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ | Envenenamento ARP |
| on-path attack/ɒn pæθ əˈtæk/ | ataque on-path |
| MAC flooding/mæk ˈflʌdɪŋ/ | Flooding de MAC |
| switch/swɪtʃ/ | interruptor |
| eavesdropping/ˈiːvzdrɒpɪŋ/ | interceptação |
| DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ | Envenenamento DNS |
| denial of service/dɪˈnaɪəl ɒv ˈsɜːvɪs/ | negativa de serviço |
| distributed denial of service/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ | denegação de serviço distribuída |
| rogue access point/rəʊɡ ˈækses pɔɪnt/ | ponto de acesso malicioso |
On-path and flooding attacks
- ARP poisoning 地址解析投毒: fake ARP messages send traffic to the adversary — an on-path attack 中间人攻击.
- MAC flooding 物理地址泛洪: overloading a switch 交换机 so it broadcasts all traffic (eavesdropping 窃听).
- The adversary reads or alters messages between two parties.
Ataques on-path e flooding
- ARP poisoning 地址解析投毒: mensagens ARP falsas enviam tráfego para o adversário — um ataque on-path 中间人攻击.
- MAC flooding 物理地址泛洪: sobrecarregar um switch 交换机 para que ele transmita todo o tráfego (eavesdropping 窃听).
- O adversário lê ou altera mensagens entre duas partes.
Redirection and denial
- DNS poisoning 域名投毒: a fake record redirects users to a malicious site.
- Smurf attack: an ICMP flood — a denial of service (DoS) 拒绝服务.
- Many machines at once = a distributed denial of service (DDoS) 分布式拒绝服务.
Redirecionamento e negação
- DNS poisoning 域名投毒: um registro falso redireciona usuários para um site malicioso.
- Smurf attack: uma inundação ICMP — um denial of service (DoS) 拒绝服务.
- Muitas máquinas ao mesmo tempo = um distributed denial of service (DDoS) 分布式拒绝服务.
Identify the network attack · Identifique o ataque de rede
Each attack has a distinct trace: ARP=two MACs for one IP; MAC flooding=switch overload; DNS=redirect; smurf=ICMP flood. · Cada ataque tem uma marca distinta: ARP=dois MACs para um IP; MAC flooding=sobrecarga de switch; DNS=redirecionamento; smurf=flood ICMP.
An adversary secretly sitting between two parties, reading their traffic, performs a(n)... · Um adversário sentando-se secretamente entre duas partes, lendo seu tráfego, realiza um(a)...
This is an on-path / man-in-the-middle attack. · Este é um ataque on-path / homem-no-meio.
One IP address shown with two different MAC addresses in a log suggests... · Um endereço IP mostrado com dois endereços MAC diferentes em um log sugere...
Duplicate MAC for one IP = ARP poisoning. · MAC duplicado para um IP = envenenamento ARP.
An unauthorised access point plugged into an open port is a ____ access point. · Um ponto de acesso não autorizado conectado a uma porta aberta é um ponto de acesso ____.
A rogue access point bypasses the firewall. · Um ponto de acesso rogue contorna o firewall.
Which attacks let an adversary eavesdrop on traffic? (Choose all) · Quais ataques permitem que um adversário espreite o tráfego? (Escolha todos)
A UPS failure is not an eavesdropping attack. · Uma falha no UPS não é um ataque de espião.
How networks get exploited
- An open port lets an attacker install a rogue access point 非法接入点.
- A rogue AP bypasses the firewall entirely.
- We rate risk by impact and the skill an exploit needs.
Como as redes são exploradas
- Uma porta aberta permite que um atacante instale um rogue access point 非法接入点.
- Um rogue AP contorna completamente o firewall.
- Avaliamos o risco pelo impacto e pela habilidade necessária para explorar.
In an on-path (man-in-the-middle) attack, both parties think they are talking directly to each other. They are actually each talking to the adversary, who quietly reads or changes every message.
Em um ataque on-path (man-in-the-middle), ambas as partes acham que estão falando diretamente uma com a outra. Na verdade, cada uma está falando com o adversário, que silenciosamente lê ou altera cada mensagem.
When many machines flood a target at once, it is a distributed denial of service (DDoS). · Quando muitas máquinas inundam um alvo ao mesmo tempo, trata-se de uma denegação de serviço distribuída (DDoS).
Many attackers at once = DDoS. · Muitos atacantes ao mesmo tempo = DDoS.
In ARP poisoning, the adversary tells the network "the target's IP belongs to MY hardware address." Traffic meant for the target now flows through the adversary first. The tell-tale sign in a log: one IP shown with two different MAC addresses.
No ARP poisoning, o adversário diz à rede "o IP-alvo pertence AO MEU endereço de hardware." O tráfego destinado ao alvo agora flui primeiro pelo adversário. O sinal revelador em um log: um IP mostrado com dois endereços MAC diferentes.
Key network attacks: ARP poisoning (eavesdrop from an on-path / man-in-the-middle position), MAC flooding (eavesdrop by forcing the switch to broadcast every frame), DNS poisoning (redirect), and smurf/DoS/DDoS (flood). Weak or open ports let an adversary add a rogue access point that bypasses the firewall.
Principais ataques de rede: ARP poisoning (eavesdrop de uma posição on-path / man-in-the-middle), MAC flooding (eavesdrop forçando o switch a transmitir cada quadro), DNS poisoning (redirecionamento) e smurf/DoS/DDoS (inundação). Portas fracas ou abertas permitem que um adversário adicione um rogue access point que contorna o firewall.