EH-03-P1: MITM Attacks Flashcards

On Path: Execution Steps

1
Q

What is the third step of an On-Path execution

A

Potentially sensitive information about a client is collected as the communication continues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Victims having no idea their communication is being intercepted is which step of the On-Path execution step

A

Step 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the first step of an On-Path execution

A

An attacking machine places itself between computers communicating with each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the DNS poisoning process?

A
  • configuring host files
  • capturing victim’s DNS request
  • Redirect the victim to a target IP
  • use ARP poisoning to position the machine in the middle
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the ARP Poisoning Process?

A
  • Exploits lack of ARP packet validation
  • Forges ARP request packets
  • Requests are sent as if by the victim
  • Updates ARP tables in the network’s nodes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Bettercap

A
  • Bettercap is a tool used for On-Path attacks.
  • Can initiate ARP poisoning and DNS spoofing
  • Sends false DNS responses to the victim
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

set

A

specifies the required parameters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

arp.spoof.target

A

specifies the target IP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

arp.spoof

A

specifies ARP spoofing actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

dns.spoof.domains

A

specifies website domains to be spoofed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

dns.spoof.address

A

specifies IP addresses for redirection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is SSL Stripping

A
  • downgrades HTTPS to HTTP

- provides plain text view of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly