Understand And Prevent MITM/Sniffing Attacks 03-24-2013, 12:08 PM
#1
Hello Hackcommunity! In this tutorial you'll learn how to prevent Sniffing and MITM attacks as a part of essential Security. First of all we need to understand the 2 terms, that are:
1) Sniffing
2) MITM Attacks (Man-In-the-Middle)
We know how packets flow in a Network which are a result of the Communication between the Client and the Server. Now don't worry If you don't know that. I'll explain it a little bit.
What is Network Flow or Client-Server Communication?
As stated in Wikipedia, Network flow is a sequence of packets from the source to the destination, or In easy words "The flow of packets from a source to a destination"
Let me explain it with the help of a diagram:
![[Image: h8ZtEBQ.png]](http://i.imgur.com/h8ZtEBQ.png)
Now consider the Source in the above definition as the Server (E.g. An HTTP Server)
Closely study the diagram, we have read that client-server communication is done by Packets. So in network flow, a client doesn't connect randomly with a server. In order to communicate and get data from it, It first has to send a "Request". So think of it as a "Request Packet". After the server has received the "Request Packet", it'll respond to the Client's Request and will send a "Response Packet" to the server. In this state the client has established a connection to the server. Lets understand this by another example:
In this example, the client wants to download the file bluedog.tar.gz from the server, these diagrams show how it does:
![[Image: 6hnYzgo.png]](http://i.imgur.com/6hnYzgo.png)
![[Image: zfQHC6i.png]](http://i.imgur.com/zfQHC6i.png)
So the final diagram would be:
![[Image: prL6cXO.png]](http://i.imgur.com/prL6cXO.png)
Till now you should have an understanding on how Client Communicates with the Server. Now similarly we shall discuss Network Sniffing.
Network Sniffing and MITM:
Normally when you use Facebook and login to your account, your browser communicates with the Facebook Server in the following way:
![[Image: mSUSnbm.png]](http://i.imgur.com/mSUSnbm.png)
As Solar Winds Describes, Network Sniffing refers to utilities that examine data packets on a network to gather data from a packet or to identify the contents of the packet. Network Sniffing utilities help identify unauthorized data on a network. Network Sniffing tools can also gather information about data flow to help administrators identify potential or existing data bottlenecks.
So we know that sniffing is a process in which a person is able to get the packets from the source and is able to analyze it or even extract information from it. But the question that arises here is,
How is the person able to get the Packets?
Well this is the part where MITM plays it's role. MITM usually means Man - In - the -Middle, so in order to intercept the packets from the source, the person must get between the communication link to and from the Server/Source. Lemme give you a diagram for that:
![[Image: zeln6cn.png]](http://i.imgur.com/zeln6cn.png)
MITM Attacks are serious when It comes to security as you might not know that your network is being sniffed but I'll discuss it later how to know if you are being sniffed. If there are many users on a single router and a attacker becomes the MITM then the attacker will be able to sniff all the packets going through the router.
Measures To Stop MITM And Sniffing:
1) The first safest method is to switch to Encrypted Protocols (SFTP, SSH, HTTPS), because it sends encrypted packets which are hardly detected by sniffer or if even detected by a sniffer, it's hard to decode the data.
2) Using a SSH Tunnel is the most peaceful way to defeat and prevent MITM/Sniffing attacks, because all your packets are being transferred from another source, Here's a diagram:
![[Image: uGFGXB9.png]](http://i.imgur.com/uGFGXB9.png)
Well this ends my tutorial on how to prevent MITM AND Sniffing attacks, In the text part I'll be including on how to detect a sniffer on you network and strengthen your network against them.
I Hope this tutorial Help
Regards,
Ex094
1) Sniffing
2) MITM Attacks (Man-In-the-Middle)
We know how packets flow in a Network which are a result of the Communication between the Client and the Server. Now don't worry If you don't know that. I'll explain it a little bit.
What is Network Flow or Client-Server Communication?
As stated in Wikipedia, Network flow is a sequence of packets from the source to the destination, or In easy words "The flow of packets from a source to a destination"
Let me explain it with the help of a diagram:
![[Image: h8ZtEBQ.png]](http://i.imgur.com/h8ZtEBQ.png)
Now consider the Source in the above definition as the Server (E.g. An HTTP Server)
Closely study the diagram, we have read that client-server communication is done by Packets. So in network flow, a client doesn't connect randomly with a server. In order to communicate and get data from it, It first has to send a "Request". So think of it as a "Request Packet". After the server has received the "Request Packet", it'll respond to the Client's Request and will send a "Response Packet" to the server. In this state the client has established a connection to the server. Lets understand this by another example:
In this example, the client wants to download the file bluedog.tar.gz from the server, these diagrams show how it does:
![[Image: 6hnYzgo.png]](http://i.imgur.com/6hnYzgo.png)
![[Image: zfQHC6i.png]](http://i.imgur.com/zfQHC6i.png)
So the final diagram would be:
![[Image: prL6cXO.png]](http://i.imgur.com/prL6cXO.png)
Till now you should have an understanding on how Client Communicates with the Server. Now similarly we shall discuss Network Sniffing.
Network Sniffing and MITM:
Normally when you use Facebook and login to your account, your browser communicates with the Facebook Server in the following way:
![[Image: mSUSnbm.png]](http://i.imgur.com/mSUSnbm.png)
As Solar Winds Describes, Network Sniffing refers to utilities that examine data packets on a network to gather data from a packet or to identify the contents of the packet. Network Sniffing utilities help identify unauthorized data on a network. Network Sniffing tools can also gather information about data flow to help administrators identify potential or existing data bottlenecks.
So we know that sniffing is a process in which a person is able to get the packets from the source and is able to analyze it or even extract information from it. But the question that arises here is,
How is the person able to get the Packets?
Well this is the part where MITM plays it's role. MITM usually means Man - In - the -Middle, so in order to intercept the packets from the source, the person must get between the communication link to and from the Server/Source. Lemme give you a diagram for that:
![[Image: zeln6cn.png]](http://i.imgur.com/zeln6cn.png)
MITM Attacks are serious when It comes to security as you might not know that your network is being sniffed but I'll discuss it later how to know if you are being sniffed. If there are many users on a single router and a attacker becomes the MITM then the attacker will be able to sniff all the packets going through the router.
Measures To Stop MITM And Sniffing:
1) The first safest method is to switch to Encrypted Protocols (SFTP, SSH, HTTPS), because it sends encrypted packets which are hardly detected by sniffer or if even detected by a sniffer, it's hard to decode the data.
2) Using a SSH Tunnel is the most peaceful way to defeat and prevent MITM/Sniffing attacks, because all your packets are being transferred from another source, Here's a diagram:
![[Image: uGFGXB9.png]](http://i.imgur.com/uGFGXB9.png)
Well this ends my tutorial on how to prevent MITM AND Sniffing attacks, In the text part I'll be including on how to detect a sniffer on you network and strengthen your network against them.
I Hope this tutorial Help

Regards,
Ex094




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
![[Image: 2YpkRjy.png]](http://i.imgur.com/2YpkRjy.png)