Re: ip adress spoofing
| From: | Andreas Pour | Date: | Fri, 10 Nov 2000 13:48:00 +0000 |
| Subject: | Re: ip adress spoofing | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-24654@lists.php.net to get a copy of this message | ||
Sylwester Zarêbski wrote:
>
> Jeroen Wesbeek wrote:
> >
> > Thanks Sylwester and Teodor,
> >
> > I also thought you couldn't, but just wanted to be sure about it :)
> > Though I'm not quite familliar with the technicalities of the packets,
> > I guess it also wouldn't be possible to spoof a get request in general?
> > You first have to create a connection before you can send
> > any HTTP requests to a webserver and therefore you can't spoof
> > your IP adress, right?
Of course you can spoof an IP address, using a "man-in-the-middle"
attack. But this is not easy, and it's even harder not to get
detected. All you need is to get control of a router in the path.
E.g., an easy place would be your ISP if you have, say, a DSL line. A
technician there could easily "spoof" your IP address by redirecting
traffic to another server or having the router itself respond to the IP
address instead of routing the packet. This may be a "weak" spoofing in
that, depending on how you look at it, it's not really a spoof but a
change in the routing tables. It only becomes a spoof if the other side
expects a particular machine to be associated with the IP address, which
of course is the case most of the time.
The less reliable way to spoof is to put a machine on the network that
snoops and detects packets not strictly being routed to it and respond
to them as if they were addressed to it. This type of attack works
really only if the "real" machine (to which the routing tables point) is
not responding, since if it does respond the original computer will get
confused as it gets two responses. One way the "evil snooper" can get
the "real" computer not to respond is to launch a DOS attack against the
"real" computer -- e.g. sending so many PING or UDP packets that the
"real" computer crashes or is otherwise unable to respond to the TCP/IP
packets from the original computer. Of course this is less successful
if the snooping computer is not guaranteed to be in the routing path
from the original to the real computer; in that case it may miss packets
intended for the real computer and not be able to reconstruct the
packets.
Anyway, I wouldn't lose sleep over this, you undoubtedly have a higher
risk of having a car crash on your drive to work :-).
Ciao,
Andreas Pour
http://www.kde.com/ : Everything KDE
http://apps.kde.com/: The Latest in KDE Applications