Bastian Ballmann Attack and Defense with Python
Total Page:16
File Type:pdf, Size:1020Kb
Bastian Ballmann Understanding Network Hacks Attack and Defense with Python Understanding Network Hacks Bastian Ballmann Understanding Network Hacks Attack and Defense with Python 123 Bastian Ballmann Uster, Switzerland Translation from the German language edition “Network Hacks - Intensivkurs”, c Springer-Verlag, 2012 ISBN 978-3-662-44436-8 ISBN 978-3-662-44437-5 (eBook) DOI 10.1007/978-3-662-44437-5 Springer Heidelberg New York Dordrecht London Library of Congress Control Number: 2014960247 © Springer-Verlag Berlin Heidelberg 2015 This work is subject to copyright. All rights are reserved by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed. Exempted from this legal reservation are brief excerpts in connection with reviews or scholarly analysis or material supplied specifically for the purpose of being entered and executed on a computer system, for exclusive use by the purchaser of the work. Duplication of this publication or parts thereof is permitted only under the provisions of the Copyright Law of the Publisher’s location, in its current version, and permission for use must always be obtained from Springer. Permissions for use may be obtained through RightsLink at the Copyright Clearance Center. Violations are liable to prosecution under the respective Copyright Law. The use of general descriptive names, registered names, trademarks, service marks, etc. in this publication does not imply, even in the absence of a specific statement, that such names are exempt from the relevant protective laws and regulations and therefore free for general use. While the advice and information in this book are believed to be true and accurate at the date of publication, neither the authors nor the editors nor the publisher can accept any legal responsibility for any errors or omissions that may be made. The publisher makes no warranty, express or implied, with respect to the material contained herein. Printed on acid-free paper Springer is part of Springer Science+Business Media (www.springer.com) For data travelers, knowledge hungry, curious, network-loving life-forms who like to explore and get to the bottom of thing. Preface Doesn’t this book explain how to break into a computer system? Isn’t that illegal and a bad thing at all? I would like to answer both questions with no (at least the second one). Knowledge is never illegal nor something bad, but the things you do with it. You as an admin, programmer, IT manager, or just an interested reader cannot protect yourself if you don’t know the techniques of the attackers. You cannot test the effectiveness of your firewalls and intrusion detection systems or other security, related software if you are not able to see your IT infrastructure through the eyes of an attacker. You cannot weigh up the danger to costs of possible security solutions if you don’t know the risks of a successful attack. Therefore, it is necessary to understand how attacks on computer networks really work. The book presents a selection of possible attacks with short source code samples to demonstrate how easy and effectively and maybe undetected a network can be infiltrated. This way you can not only learn the real techniques but present them to your manager or employer and help them in the decision if it would make sense to care a little bit more about IT security. At the end of the book, you should be able to not only understand how attacks on computer networks really work but also to modify the examples to your own environment and your own needs. Sure, the book also tells those bad guys how to crack the net and write their own tools, but IT security is a sword with two sharp blades. Both sides feed themselves off the same pot of knowledge, and it is a continuous battle, which the protecting side can never dream of winning if it censors itself or criminalizes their knowledge! Uster, Switzerland Bastian Ballmann vii Contents 1 Installation .................................................................. 1 1.1 The Right Operating System......................................... 1 1.2 The Right Python Version ........................................... 1 1.3 Development Environment .......................................... 2 1.4 Python Modules ...................................................... 3 2 Network 4 Newbies ......................................................... 5 2.1 Components .......................................................... 5 2.2 Topologies ............................................................ 5 2.3 ISO/OSI Layer Model................................................ 7 2.4 Ethernet ............................................................... 8 2.5 VLAN................................................................. 9 2.6 ARP ................................................................... 10 2.7 IP ...................................................................... 10 2.8 ICMP.................................................................. 12 2.9 TCP ................................................................... 12 2.10 UDP ................................................................... 16 2.11 An Example Network ................................................ 16 2.12 Architecture........................................................... 17 2.13 Gateway............................................................... 18 2.14 Router ................................................................. 18 2.15 Bridge ................................................................. 19 2.16 Proxies ................................................................ 19 2.17 Virtual Private Networks ............................................. 19 2.18 Firewalls .............................................................. 20 2.19 Man-in-the-Middle-Attacks.......................................... 21 3 Python Basics ............................................................... 23 3.1 Every Start Is Simple................................................. 23 3.2 The Python Philosophy .............................................. 24 3.3 Data Types ............................................................ 25 3.4 Data Structures ....................................................... 26 ix x Contents 3.5 Functions ............................................................. 27 3.6 Control Structures .................................................... 28 3.7 Modules............................................................... 30 3.8 Exceptions ............................................................ 31 3.9 Regular Expressions.................................................. 31 3.10 Sockets ................................................................ 33 4 Layer 2 Attacks ............................................................. 35 4.1 Required Modules .................................................... 35 4.2 ARP-Cache-Poisoning ............................................... 35 4.3 ARP-Watcher ......................................................... 39 4.4 MAC-Flooder......................................................... 41 4.5 VLAN Hopping ...................................................... 42 4.6 Let’s Play Switch ..................................................... 42 4.7 ARP Spoofing Over VLAN Hopping ............................... 43 4.8 DTP Abusing ......................................................... 44 4.9 Tools .................................................................. 45 4.9.1 NetCommander ............................................. 45 4.9.2 Hacker’s Hideaway ARP Attack Tool ..................... 45 4.9.3 Loki ......................................................... 45 5 TCP/IP Tricks............................................................... 47 5.1 Required Modules .................................................... 47 5.2 A Simple Sniffer ..................................................... 47 5.3 Reading and Writing PCAP Dump Files ............................ 49 5.4 Password Sniffer ..................................................... 51 5.5 Sniffer Detection ..................................................... 53 5.6 IP-Spoofing ........................................................... 54 5.7 SYN-Flooder ......................................................... 55 5.8 Port-Scanning......................................................... 56 5.9 Port-Scan Detection .................................................. 59 5.10 ICMP-Redirection .................................................... 61 5.11 RST Daemon ......................................................... 63 5.12 Automatic Hijack Daemon........................................... 65 5.13 Tools .................................................................. 68 5.13.1 Scapy ........................................................ 68 6 WHOIS DNS?............................................................... 73 6.1 Protocol Overview ................................................... 73 6.2 Required Modules .................................................... 74 6.3 Questions About Questions .......................................... 74 6.4 WHOIS ..............................................................