Soru

Zorluk: OrtaCommon Network Attack Types and Vectors

A network security analyst observes anomalous traffic on an internal enterprise subnet. When an end user accidentally mistypes an internal file server hostname, packet logs show an unauthorized host on the local broadcast domain immediately responding to the link-local multicast request before the DNS query completes, prompting the user's workstation to attempt authentication. Which of the following attack vectors is occurring?

  1. LLMNR/NBT-NS poisoningCevap
  2. B
    DNS cache poisoning
  3. C
    ARP poisoning
  4. D
    Port forwarding mismatch

Cevap

LLMNR/NBT-NS poisoning
LLMNR and NBT-NS poisoning exploits the fallback behavior of operating systems when standard DNS lookup fails (such as when a hostname is mistyped). An attacker listening on the local broadcast domain answers the multicast query claiming to be the target resource, tricking the client into sending authentication hashes.

Adım Adım Çözüm

1
Analyze the observed attack mechanism
Identified that an unauthorized host is responding to link-local multicast requests generated when standard DNS name resolution fails.
Windows operating systems fall back to LLMNR and NBT-NS broadcast/multicast protocols on the local link when a hostname cannot be resolved via DNS.
2
Distinguish between Layer 2/3 address spoofing and multicast name resolution spoofing
The malicious host actively claims ownership of the mistyped hostname during the link-local fallback phase to capture authentication hashes.
This behavior specifically characterizes LLMNR/NBT-NS poisoning, contrasting with ARP spoofing (Layer 2 IP-to-MAC mapping) or DNS server record manipulation.

Anahtar Kavram

LLMNR and NBT-NS Poisoning
Tahmini Süre:1m 30s
Bu soruyu puanla