A network security analyst observes anomalous traffic on an internal enterprise subnet. When an end user accidentally mistypes an internal file server hostname, packet logs show an unauthorized host on the local broadcast domain immediately responding to the link-local multicast request before the DNS query completes, prompting the user's workstation to attempt authentication. Which of the following attack vectors is occurring?
- LLMNR/NBT-NS poisoningCevap
- BDNS cache poisoning
- CARP poisoning
- DPort forwarding mismatch
Cevap
LLMNR/NBT-NS poisoning
LLMNR and NBT-NS poisoning exploits the fallback behavior of operating systems when standard DNS lookup fails (such as when a hostname is mistyped). An attacker listening on the local broadcast domain answers the multicast query claiming to be the target resource, tricking the client into sending authentication hashes.
Adım Adım Çözüm
Anahtar Kavram
LLMNR and NBT-NS Poisoning
Tahmini Süre:1m 30s