Soru

Zorluk: OrtaNetwork and Wireless Attack Indicators

During a security investigation following alerts from an enterprise Network Intrusion Detection System (NIDS), a security analyst inspects captured traffic headers from a user workstation. The network logs reveal that outbound TCP port 443 connections destined for an internal authentication portal are systematically terminated via forged TCP Reset (RST) packets, while concurrent HTTP 302 response headers redirect the user's browser to submit credentials in cleartext over port 80. Which of the following network attacks is best demonstrated by these observed technical indicators?

  1. An on-path attack executing SSL stripping to downgrade secure sessions to unencrypted communicationsCevap
  2. B
    A Domain Name System (DNS) amplification attack leveraging open resolvers to flood the client network
  3. C
    A MAC flooding attack attempting to exhaust switch memory tables to force traffic broadcasting
  4. D
    A wireless disassociation attack sending spoofed management frames to sever client connections

Cevap

An on-path attack executing SSL stripping to downgrade secure sessions to unencrypted communications.
The scenario describes an on-path (man-in-the-middle) attack utilizing SSL stripping. In an SSL stripping attack, the threat actor sits between the client and the destination server, intercepting initial HTTPS connection attempts (port 443) and forcing the client to communicate over unencrypted HTTP (port 80) via HTTP 302 redirects. This enables the attacker to view and harvest credentials transmitted in cleartext.

Adım Adım Çözüm

1
Analyze the observed traffic indicators from the NIDS packet capture.
Identified TCP port 443 RST packets paired with HTTP 302 redirect headers targeting port 80.
Understanding packet behaviors helps isolate whether the attack operates at Layer 2, Layer 3/4, or Layer 7.
2
Evaluate the mechanism used to manipulate the client session.
The attacker actively interferes with HTTPS establishment and redirects traffic to an unencrypted channel.
This behavior specifically characterizes protocol downgrade attacks designed to bypass TLS transport security.
3
Match the observed indicators to the corresponding attack taxonomy classification.
SSL stripping (an on-path attack variant) intercepting secure sessions.
SSL stripping replaces secure HTTPS links with plain HTTP links to capture transmitted credentials in cleartext.

Anahtar Kavram

SSL/TLS Stripping and On-Path Network Attack Indicators
Tahmini Süre:1m 30s
Bu soruyu puanla