|
|
04/11/2004
-----------------------------------
1. Denial of service (DOS)
, . -
,
,
-
. . ,
; -
..
- . DOS
Floods, ICMP flooding, Identification flooding
.
2. Hack
, -
, -
, , Ports
scan, DOS-.
-
-
DOS-.
3. Floods
- "".
floods
ICMP ( ) UDP , -
(). -
.
4. SYN flooding
SYN- - "" -
. , TCP/IP -
. C-SYN-
S-SYN/CACK-, SYN_RECEIVED
.
S-ACK, ,
ESTABLISHED. RFC
, -
SYN-, ,
. SYN
,
.
. ( -
) . -
. , -
2400 bps, -
20-30 ,
. ,
, telnet ftp. -
,
.
, (
"SYN-ACK") . NT 3.5-4.0
5 - 3, 6, 12, 24
48 . 96 -
, , -
. - 189 .
5. ICMP flooding (flood ping)
- " ".
-
ICMP ( ). -
-
. : -
,
. ICMP- -
ECHO REQUEST, .
- ICMP ECHO
REPLY. , ping .
-
, .
6. Identification flooding (identd)
. ICMP
flooding, ,
(TCP 113).
..
, .
7. DNS flooding DNS scan
, Internet. -
DNS ,
,
, -
. DNS scan. , , -
, .. ,
, , -
. -
.
8. Ports scan
,
. .
<> -
;
floods.
9. Unreachable (dest_unreach, ICMP type 3)
, -
ICMP type 3, ,
.. "" . ICMP
type 3 , -
. ICMP type 3 .
10. WinNuke
Hp p TCP
cp pp p p (Out Of Band)
. H p p TCP p
urgent pointer. PC Windows p-
p NetBIOS, p
3 IP p: 137, 138, 139. ,
Windows 139 p OutOf-
Band , p NetBIOS-
p pp . Win-
dows 95 p,
pp TCP/IP p -
pp C. NT 4.0 p pp, NT 4.0
p p p.
11. Boink (Bonk, Teardrop, new Tear/Tear2)
IP -
. -
, ,
.
,
, , -
. .
IP -
, 64
( IP 64 ).
Windows.
Windows NT,
icmp-fix, "" .
IP ,
, -
, , .
12. PingOfDeath (Ssping, IceNuke, Jolt)
: -
p ICMP pp (64KB).
Windows-
, .
C
Unix. , WinNuke
Windows ,
MacOS p Unix.
, firewall ICMP ,
firewall , ,
spoofing, fire-
wall. PingOfDeath , -
64KB , p-
p p.
13. Land
TCP/IP -
. -
- TCP- SYN,
. , -
,
"-
" . -
Cisco Systems,
.
14. Pong
Floods , ,
IP- ( )
. .
15. Puke
ICMP
unreachable error ( ),
( IRC).
16. Smurf
ICMP
-. ,
, -
-, -
, , -
. broadcast ""
broadcast- , -
"" - | |. smurf
.
17. UDP bomb
UDP
.
.
18. Fuzzy
IP , -
(TCP, UDP, ICMP) Internet.
-
, -
.
19. Dummy DNS
Internet DNS-
DNS-.
DNS-, UDP- ,
ID DNS-
, , DNS- DNS-
UDP-, IP- -
IP- DNS-. -
, -
"" . -
DNS-. , -
DNS-.
( DNS- -
).
Internet.
20. Dummy DNS for host
Internet -
"" DNS- .
DNS-
DNS DNS-. ,
Internet "" DNS-.
, DNS- -
UDP, -
. ,
DNS- , , -, -
IP- IP- DNS-,
-, DNS- ,
DNS-, -, DNS-
UDP, DNS- (
), , -, DNS- -
DNS (ID)
, DNS- ( -
). ,
DNS-,
UDP-, . -
,
,
. -
DNS-,
,
( - ID 1). -
(),
, - .
( "") -
DNS-
DNS- UDP-. DNS-
IP- IP- .
.
( ) ,
DNS-,
, ,
DNS-,
DNS-.
-
, , IP- , -
, , ,
(, , )
. , -
, DNS,
Internet
.
Internet,
DNS.
21. Dummy DNS for server
Internet -
"" DNS - DNS - -
. DNS- , ,
DNS-
, DNS--
, ro-
ot.cache. , , DNS- -
, , -
, DNS-
DNS-. ,
Dummy DNS for host, DNS-. ,
, DNS--
DNS-
DNS DNS-. -
DNS-.
DNS-
IP- . -
IP- -
, DNS. ,
DNS-, ,
,
, , - -
. , DNS-
, -
-.
DNS- , -
, DNS-
DNS- ( "" -
), - -
, ,
, DNS-,
, -
, .
, DNS--
, DNS- -
, , , Internet -
., , -
DNS- DNS-, -
"" DNS-, -
DNS-. -
, , -
. DNS-, -
DNS-,
(ID).
.
DNS- . ,
216 ID
- . -
, DNS- DNS- 53 .
, -
DNS- ""
DNS , ,
, DNS-
( DNS-). DNS- -
, DNS- -
-
DNS-.
. ,
, DNS- DNS--
DNS-
.
.
22. Syslog spoofing
. syslog -
,
- -
.
23. IP spoofing
.
-
, .
,
. -
TCP :
sequence number ( C-SYN),
, -
(C-ACK) sequence number (S-SYN).
(S-ACK). -
.
sequence number
acknowledge number.
. ,
, sequence number (S-SYN -
) .
TCP/IP. ,
, (, -
) sequence
number . TCP/IP -
sequence number,
. , , A
B, , B
"rlogin A" A, . ,
C. A -
, B C - . - -
B ,
. , -
B. -
, ,
.
B, , A (
). IP-, -
, A, sequ-
ence number . IP-, -
B. A -
sequence number, B. -
B ( ),
, , . -
, sequence number B. -
"" A, B -
S-ACK (,
, sequence number -
, A). , -
sequence number , -
. -
IP-, . , -
rsh, -
.rhosts /etc/passwd -
.
24. Host spoofing
ICMP,
.
redirect.
redi-
rect- . -
,
, ,
, , redirect.
-
Internet.
25. Dummy ARP server
Internet IP, -
.
IP , ,
.
. Internet IP
Ethernet ARP (Address Resolution
Protocol). Ether-
net- , ,
Ethernet- . ,
-
ARP-,
. , -
ARP-, Ethernet-.
ARP-,
, (, -
), , ,
"" .
26. IP Hijacking
- , -
IP-. ,
sequence number acknow-
ledge number ( IP-).
, -
. "-
", sequence number
acknowledge number -
, . , "" , -
,
.
, , ,
, , -
.
27. UDP storm
,
UDP-, 7 ("", ), 19
("", -
) (date etc).
UDP-, -
7, - 19-, -
, ,
( 127.0.0.1). , 19-
, 7.
19 . -
-
. , UDP-
.
28. Traffic analysis (sniffing)
. -
,
. ,
. -
, -
, /
.
, .
29. Brute Force
" ",
,
, -
. -
. brute force -
" ".
30. Back Orifice (NetBus,Masters of Paradise )
, ( -
) .
- , , 31337, -
. .
-
, : , ,
; , -
; , , ; -
CD-ROM-;
,
. ,
.. Back
Orifice , , -
.
31. Spam
-
. -
-
; , -
;
" ", -
.
32. Virus
, ,
, .
, . -
""
-
; -
-
; www-,
; - .
33. Trojan horse
, ,
, , . -
, , .
.
" " ( -
). - "-
"
, ,
. -
, , -
, .
"" -
, " ". -
, , , - -
: ,
.
, -
.
www-, BBS -
, ! - , -
.
-
, , |
300% - -
|. " " ,
.
" " -
.
, - -
. -
.. - -
, .
| : | |