ETTERCAP - The Easy Tutorial - ๋Œ€์‘์ฑ…

Ettercap Countermeasures
์ตœ์ข… ์—…๋ฐ์ดํŠธ: Jul 21 2011


Tool
Install
Ergonomy
Forum



Details Ettercap์€ ๋ฌด์—‡์ธ๊ฐ€?
์„ค์น˜๋ฐฉ๋ฒ•
ARP ํฌ์ด์ฆˆ๋‹
์ค‘๊ฐ„์ž ๊ณต๊ฒฉ (MITM, Man-in-the-middle Attack)
ํ†ต๊ณ„
๋Œ€์‘์ฑ…

Korean translation by Youngbin Benjamin Im helped by powerhan96.



โš ๏ธโš ๏ธโš ๏ธ
Please check our website about
attractions in Western Switzerland !! (Please use english translation).

โš ๏ธโš ๏ธโš ๏ธ
Merci de consulter notre site sur les
activitรฉs ร  faire en Suisse romande !!


ARP ํฌ์ด์ฆˆ๋‹์„ ํšจ๊ณผ์ ์œผ๋กœ ๋ฐฉ์–ดํ•œ๋‹ค๋Š” ๊ฒƒ์€ ์‰ฌ์šด ์ผ์ด ์•„๋‹ˆ๋‹ค. ARP ํ”„๋กœํ† ์ฝœ์€ ํŒจํ‚ท์„ ์‹ค์งˆ์ ์œผ๋กœ ๋ณด๋‚ด๋Š” ์„œ๋ฒ„์™€์˜ ์—ฐ๊ฒฐ ๋ฌด๊ฒฐ์„ฑ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.
์ƒํ™ฉ์€ ์ด๋Ÿฌํ•˜์ง€๋งŒ ์ด๋Ÿฐ ๋ฐฉ๋ฒ•์„ ์•…์šฉํ•˜๋Š” ์Šคํ‘ธํผ์— ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋Š” ๋ช‡ ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์„ ์ œ์•ˆํ•˜๋ ค๊ณ  ํ•œ๋‹ค.

1. ๊ณ ์ • ARP 2. ๊ฐ์‹œํˆด 3. ํฌํŠธ ๋ณด์•ˆ 4. ๊ฒฐ๋ก 



1. ๊ณ ์ • ARP

๊ณ ์ • ARP๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค๋Š” ๊ฒƒ์€ ์ง์ ‘ IP์™€ MAC์ฃผ์†Œ๋ฅผ ๋งคํ•‘ํ•œ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.

์œˆ๋„์šฐ PC

C:\Documents and Settings\administrator>arp -s 192.168.1.1   11-22-33-44-11-11
ARP ์บ์‹œ ํ…Œ์ด๋ธ”์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋ณผ ์ˆ˜ ์žˆ๋‹ค:

C:\Documents and Settings\administrator>arp -a
Interfaceย : 192.168.1.2 --- 0x2
Internet Address
192.168.1.1
192.168.1.100
Physical Address
11-22-33-44-11-11
11-22-33-44-99-99
Type
static
dynamic
๋ฆฌ๋ˆ…์Šค PC

#arp -s 192.168.1.1 11:22:33:44:11:11
ARP ์บ์‹œ ํ…Œ์ด๋ธ”์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋ณผ ์ˆ˜ ์žˆ๋‹ค:

#arp
Address
192.168.1.1
HWtype
ether
HWaddress
11:22:33:44:11:11
Flags Mask
CM
Iface
eth0
์‹œ์Šค์ฝ” ๋ผ์šฐํ„ฐ

router#configure terminal
router(config)#arp 192.168.1.2 1122.3344.5566 ARPA
๊ณ ์ •์ ์ธ IP โ€“ MAC์ฃผ์†Œ ๋งคํ•‘์„ ์‚ฌ์šฉํ•˜๋ฉด ARP ํฌ์ด์ฆˆ๋‹์„ ๋ง‰์„ ์ˆ˜ ์žˆ์ง€๋งŒ ๋‘ ๊ฐ€์ง€์˜ ํฐ ๋‹จ์ ์ด ์žˆ๋‹ค.
-
 
-
์ผ์ผ์ด ์„ค์ •ํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์šด์˜์ž์—๊ฒŒ ์ถ”๊ฐ€์ ์ธ ๋ถ€ํ•˜๊ฐ€ ๋ฐœ์ƒํ•˜๊ณ  ๋…ธํŠธ๋ถ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ์ฒ˜๋Ÿผ ์‚ฌ์šฉ์ž๊ฐ€ ๋นˆ๋ฒˆํžˆ ๋ฐ”๋€” ์ˆ˜ ์žˆ๋Š” ํ™˜๊ฒฝ์—์„œ๋Š” ์ด๋Ÿฐ ๋ฐฉ๋ฒ•์ด ๋ถˆ๊ฐ€๋Šฅ ํ•  ์ˆ˜ ์žˆ๋‹ค.
ํฌํŠธ ํ›”์น˜๊ธฐ(port stealing)์™€ ๊ฐ™์€ ๋‹ค๋ฅธ ์ข…๋ฅ˜์˜ ARP ๊ณต๊ฒฉ์€ ๋ง‰์„ ์ˆ˜ ์—†๋‹ค.
Top of the page



2. ๊ฐ์‹œํˆด

Arpwatch

Arpwatch๋Š” ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ ARP ํ™œ๋™์„ ๋ชจ๋‹ˆํ„ฐ๋ง ํ•˜๋Š” ํˆด๋กœ์จ ํŠนํžˆ, MAC์ฃผ์†Œ์™€ IP์ฃผ์†Œ ์กฐํ•ฉ์— ๋ณ€๊ฒฝ์ด ์ƒ๊ฒผ์„ ๋•Œ ์ด๋ฅผ ๊ฐ์ง€ํ•˜๋Š”๋ฐ ์œ ์šฉํ•˜๋‹ค. ARP ์Šคํ‘ธํ•‘๊ณผ ๊ฐ™์€ ARP ๊ณต๊ฒฉ์ด ์ด๋ฃจ์–ด์ง€๋ ค๊ณ  ํ•  ๋•Œ๋‚˜ ์˜์‹ฌ๋˜๋Š” ARP ํ™œ๋™์ด ๋ชจ๋‹ˆํ„ฐ๋ง ๋˜์—ˆ์„ ๋•Œ ๊ด€๋ฆฌ์ž์—๊ฒŒ ๋ฉ”์ผ์ด ๋ฐœ์†ก๋œ๋‹ค. (Arpwatch์—์„œ ARP ๋งคํ•‘์ด ๋ณ€๊ฒฝ๋˜๋Š” ๊ฒƒ์„ flip-flop์ด๋ผ๊ณ  ํ•œ๋‹ค).

#apt-get install arpwatch
Arpwatch๋Š” ๋””ํดํŠธ๋กœ /var/log/syslog๋กœ ๋กœ๊ทธ๋ฅผ ๋‚จ๊ธด๋‹ค. โ€œtail /var/log/syslogโ€๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋กœ๊ทธ๋ฅผ ์‹ค์‹œ๊ฐ„ ๊ฐ์‹œํ•  ์ˆ˜ ์žˆ๋‹ค.
์„ค์ •ํŒŒ์ผ์€ /etc/arpwatch.conf ํŒŒ์ผ์ด๋‹ค.

Ettercap

Ettercap์„ ๊ทธ๋ž˜ํ”ฝ๋ชจ๋“œ๋กœ ์ธ์Šคํ†จํ•œ๋‹ค.

#apt-get install ettercap-gtk
Ettercap์„ ๊ทธ๋ž˜ํ”ฝ๋ชจ๋“œ๋กœ ์‹คํ–‰ํ•œ๋‹ค.

#ettercap -G
Sniff -> Unified sniffing...
Unified sniffing sniff man in the middle attack openmaniak ettercap
Unified sniffing sniff man in the middle attack  openmaniak ettercap
 
 
 
 
 

Plugins -> Manage the plugins
Arp_corp ํ”Œ๋กœ๊ทธ์ธ์„ ํด๋ฆญํ•˜์—ฌ ํ™œ์„ฑํ™” ์‹œํ‚จ๋‹ค.

Manage the plugins plugins man in the middle attack  openmaniak ettercap

Start -> Start Sniffing
Start Sniffing  start man in the middle attack  openmaniak ettercap

Snort IDS

Snort IDS์™€ ๊ฐ™์€ ์นจ์ž…ํƒ์ง€์‹œ์Šคํ…œ์€ ARP์˜ ๋น„์ •์ƒ์ ์ธ ํ™œ๋™์„ ๊ฐ์‹œํ•˜๋ฉฐ ๊ด€๋ฆฌ์ž์—๊ฒŒ ๋ฉ”์ผ์„ ๋ฐœ์†กํ•˜์—ฌ ์•Œ๋ ค์ค€๋‹ค.

Top of the page



3. ํฌํŠธ ๋ณด์•ˆ

ํฌํŠธ-๋ณด์•ˆ์€ ๋ช‡๋ช‡ ๊ณ ๊ธ‰ ์Šค์œ„์น˜(High-end switches)์—์„œ ์ œ๊ณต๋˜๋Š” ๊ธฐ๋Šฅ์ด๋‹ค.
ํŠน์ • MAC์ฃผ์†Œ๋ฅผ ๊ฐ€์ง„ ๋””๋ฐ”์ด์Šค๋งŒ ์Šค์œ„์น˜ ํฌํŠธ์— ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•˜๋‹ค. ๋งŒ์•ฝ ์ธ์ฆ๋˜์ง€ ์•Š์€ ์ ‘์†์ด ์‹œ๋„๋  ๊ฒฝ์šฐ, ์Šค์œ„์น˜์—์„œ ๊ด€๋ฆฌ์ž์—๊ฒŒ SNMPํŠธ๋žฉ์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฒฝ๊ณ ๋ฅผ ๋ณด๋‚ด๊ฑฐ๋‚˜ ์ž˜๋ชป๋œ ํฌํŠธ๋ฅผ ๋ฐ”๋กœ ๋‹ซ์•„๋ฒ„๋ฆด ์ˆ˜๋„ ์žˆ๋‹ค.

์•„๋ž˜๋Š” ์‹œ์Šค์ฝ” ์Šค์œ„์น˜์—์„œ first port(FastEthernet 0/1)๋ฅผ ํฌํŠธ-๋ณด์•ˆ์œผ๋กœ ์„ค์ •ํ•œ ์˜ˆ์ œ์ด๋‹ค.
์Šค์œ„์น˜ ํฌํŠธ์—์„œ sticky ํ‚ค์›Œ๋“œ๋ฅผ ์‚ฌ์šฉํ•ด ์Šน์ธ๋˜๋Š” ์ฒซ๋ฒˆ์งธ ๊ณ ์œ  MAC์ฃผ์†Œ๋งŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ์„ค์ •ํ•œ๋‹ค. ๋งŒ์•ฝ ์Šค์œ„์น˜ ํฌํŠธ์˜ first port์—์„œ ๋‹ค๋ฅธ MAC์ฃผ์†Œ๊ฐ€ ๊ฐ์ง€๋˜๋ฉด ์ฆ‰์‹œ ํฌํŠธ๋ฅผ ๊บผ๋ฒ„๋ฆฌ๊ฒŒ ๋œ๋‹ค.

Switch# configure terminal
Switch(config)# interface FastEthernet 0/1
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security maximum 1
Switch(config-if)# switchport port-security violation shutdown
์Šค์œ„์น˜ ์„ค์ • ์ž‘์—…์ด ๋๋‚ฌ๋‹ค๋ฉด 1122.3344.5566์˜ MAC์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ๋””๋ฐ”์ด์Šค๋ฅผ FastEthernet 0/1 ํฌํŠธ๋กœ ์—ฐ๊ฒฐํ•œ๋‹ค. ์ง€๊ธˆ ์ด ํฌํŠธ๋Š” ํ•˜๋‚˜์˜ MAC์ฃผ์†Œ๋งŒ ์Šน์ธํ•˜๋„๋ก ์„ค์ •์ด ๋˜์–ด์žˆ๋‹ค.

Switch# show port-security
Secure Port   MaxSecureAddr   CurrentAddr   SecurityViolation   Security Action
                         (Count)          (Count)            (Count)
---------------------------------------------------------------------------
   Fa1/0/1               1                    1                    0          Shutdown
---------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port) : 0
Max Addresses limit in System (excluding one mac per port) : 6272

Switch# show port-security interface FastEthernet 0/1
Port Security
Port Status
Violation Mode
Aging Time
Aging Type
SecureStatic Address Aging
Maximum MAC Addresses
Total MAC Addresses
Configured MAC Addresses
Sticky MAC Addresses
Last Source Address:Vlan
Security Violation Count
:
:
:
:
:
:
:
:
:
:
:
:
Enabled
Secure-up
Shutdown
0 mins
Absolute
Disabled
1
1
0
1
1122.3344.5566:1
0
Switch#show port-security address
          Secure Mac Address Table
----------------------------------------------------------------------------
Vlan    Mac Address        Type                  Ports            Remaining Age
                                                                              (mins)
----    -----------          ----                    -----          -------------
1        1122.3344.5566    SecureSticky        Fa0/1              -
----------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port) : 0
Max Addresses limit in System (excluding one mac per port) : 6272


ํ˜„์žฌ ์—ฐ๊ฒฐ๋œ ์žฅ์น˜(MAC: 1122.3344.5566)์˜ ์—ฐ๊ฒฐ์„ ํ•ด์ œํ•˜๊ณ  ๋‹ค๋ฅธ ์žฅ์น˜(MAC: 1122.3344.9999)๋ฅผ ์—ฐ๊ฒฐํ•œ๋‹ค. ์•„๋ž˜์™€ ๊ฐ™์ด ์Šค์œ„์น˜์—์„œ first port๋ฅผ ๋ฐ”๋กœ ๋„๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์œผ๋ฉฐ err-disable ์ƒํƒœ๋กœ ๋ณ€๊ฒฝํ•œ๋‹ค.

Switch# show port-security interface FastEthernet 0/1
Port Security
Port Status
Violation Mode
Aging Time
Aging Type
SecureStatic Address Aging
Maximum MAC Addresses
Total MAC Addresses
Configured MAC Addresses
Sticky MAC Addresses
Last Source Address:Vlan
Security Violation Count
:
:
:
:
:
:
:
:
:
:
:
:
Enabled
Secure-down
Shutdown
0 mins
Absolute
Disabled
1
1
0
1
1122.3344.9999:1
0
Switch#show logging
00:06:28:
 
00:06:28
 
00:06:29:
 
00:06:30:
%PM-4-ERR_DISABLE: psecure-violation error detected on Fa0/1, putting Fa0/1 in err-disable state
%PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 1122.3344.9999 on port FastEthernet0/1.
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down
%LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to down
Switch#show interfaces status | include 0/1
Port
-------
Fa0/1
Name
------------------
 
Status
------------
err-disabled
Vlan
--------
1
Duplex
------
auto
Speed
-------
auto
Type
----
10/100BaseTX
๋งŒ์•ฝ ํฌํŠธ์—์„œ err-disable ์ƒํƒœ๋ฅผ ๋‹ค์‹œ ํ™œ์„ฑํ™” ํ•˜๋ ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋œ๋‹ค:

Switch# configure terminal
Switch(config)# interface FastEthernet 0/1
Switch(config-if)# shutdown
Switch(config-if)# no shutdown
ํฌํŠธ-๋ณด์•ˆ ํ™œ๋™์€ ARP ์Šคํ‘ธํ•‘์„ ๋ง‰์ง€๋Š” ๋ชปํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ณต๊ฒฉ์ž๊ฐ€ ๋„คํŠธ์›Œํฌ์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ์„ ์ค„์—ฌ์ค€๋‹ค.



4. ๊ฒฐ๋ก 

ARP ์Šคํ‘ธํ•‘์„ ์™„๋ฒฝํžˆ ๋ง‰์„ ์ˆ˜ ์žˆ๋Š” ๋งˆ๋ฒ• ๊ฐ™์€ ํ•ด๊ฒฐ์ฑ…์€ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์—ฌ๋Ÿฌ ๊ณต๊ฒฉ์„ ์‚ฌ์ „์— ๋ฐฉ์ง€ํ•  ์ˆ˜ ์žˆ๋Š” ๋ช‡ ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์„ ์•„๋ž˜์— ์ œ์•ˆํ•ด ๋ณด๊ฒ ๋‹ค.
ARP ์Šคํ‘ธํ•‘์„ ์™„๋ฒฝํžˆ ๋ง‰์„ ์ˆ˜ ์žˆ๋Š” ๋งˆ๋ฒ• ๊ฐ™์€ ํ•ด๊ฒฐ์ฑ…์€ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์—ฌ๋Ÿฌ ๊ณต๊ฒฉ์„ ์‚ฌ์ „์— ๋ฐฉ์ง€ํ•  ์ˆ˜ ์žˆ๋Š” ๋ช‡ ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์„ ์•„๋ž˜์— ์ œ์•ˆํ•ด ๋ณด๊ฒ ๋‹ค.
ํฌํŠธ ๋ณด์•ˆ์„ ํ†ตํ•ด ์ œํ•œ์ ์ธ ๋„คํŠธ์›Œํฌ๋ฅผ ๊ตฌ์„ฑํ•˜๊ฑฐ๋‚˜ ๋˜๋Š” ๋” ๋‚˜์•„๊ฐ€ RADIUS์™€ ๊ฐ™์€ ์„œ๋ฒ„์ธ์ฆ ํ”„๋กœ๊ทธ๋žจ์„ ํ†ตํ•ด ์ธ์ฆ๋œ PC๋งŒ ์ ‘๊ทผํ•˜๋„๋ก ํ•˜๋Š” 802.1x ํ”„๋กœํ† ์ฝœ ๊ธฐ๋ฐ˜์˜ ํ™˜๊ฒฝ์„ ๊ตฌ์„ฑํ•œ๋‹ค.
IDS์™€ ๊ฐ™์€ ๋„คํŠธ์›Œํฌ ๊ฐ์‹œ ํˆด์„ ์‚ฌ์šฉํ•œ๋‹ค.
Pirate: ์‚ฌ์ „์  ์˜๋ฏธ๋Š” ํ•ด์ ์ด๋‹ค. ์œ„์˜ ๋ฌธ์„œ์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์˜๋ฏธ๋Š” ์ธ์ฆ๊ณผ์ • ์—†์ด ๊ด€๋ฆฌ์ž ๋ชจ๋ฅด๊ฒŒ ๋„คํŠธ์›Œํฌ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์‚ฌ๋žŒ์„ ์˜๋ฏธํ•œ๋‹ค.

Top of the page