<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Security</title>
	<atom:link href="http://laurasecurity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://laurasecurity.wordpress.com</link>
	<description>A security solution is as strong as its weakest link</description>
	<lastBuildDate>Wed, 06 Aug 2008 20:30:55 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='laurasecurity.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/93f4b5984c77ba5eb1f0930b3274de35?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Security</title>
		<link>http://laurasecurity.wordpress.com</link>
	</image>
			<item>
		<title>Local IP Spoofing using Man-in-the-Middle Attack</title>
		<link>http://laurasecurity.wordpress.com/2008/08/04/local-ip-spoofing-using-man-in-the-middle-attack/</link>
		<comments>http://laurasecurity.wordpress.com/2008/08/04/local-ip-spoofing-using-man-in-the-middle-attack/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 17:01:00 +0000</pubDate>
		<dc:creator>Laura Cristina Gheorghe</dc:creator>
				<category><![CDATA[IP Spoofing]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[garp]]></category>
		<category><![CDATA[hub]]></category>
		<category><![CDATA[Local IP Spoofing]]></category>
		<category><![CDATA[Man in the Middle]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[span]]></category>

		<guid isPermaLink="false">http://laurasecurity.wordpress.com/?p=12</guid>
		<description><![CDATA[The attacker is on the same subnet as the target system.
Variants:
1) The attacker could send Gratuitous ARP (GARP) to clam that the attacker&#8217;s Layer 2 MAC address is the MAC address of the nex-hop router. So, the attacker would capture all the traffic and forward it to the legitimate next-hop router.
2) The attacker can connect [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=laurasecurity.wordpress.com&blog=4399967&post=12&subd=laurasecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The attacker is on the same subnet as the target system.</p>
<p>Variants:</p>
<p>1) The attacker could send Gratuitous ARP (GARP) to clam that the attacker&#8217;s Layer 2 MAC address is the MAC address of the nex-hop router. So, the attacker would capture all the traffic and forward it to the legitimate next-hop router.</p>
<p>2) The attacker can connect a hub to the network segment that carries the traffic the attacker wants to capture.</p>
<p><a href="http://laurasecurity.files.wordpress.com/2008/08/picture-4.png"><img class="alignnone size-full wp-image-13" src="http://laurasecurity.files.wordpress.com/2008/08/picture-4.png?w=509&#038;h=179" alt="" width="509" height="179" /></a></p>
<p>3)The attacker could connect to a Switch Port Analyzer (SPAN) port to capture all the traffic.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/laurasecurity.wordpress.com/12/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/laurasecurity.wordpress.com/12/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/laurasecurity.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/laurasecurity.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/laurasecurity.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/laurasecurity.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/laurasecurity.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/laurasecurity.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/laurasecurity.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/laurasecurity.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/laurasecurity.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/laurasecurity.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=laurasecurity.wordpress.com&blog=4399967&post=12&subd=laurasecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://laurasecurity.wordpress.com/2008/08/04/local-ip-spoofing-using-man-in-the-middle-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/763c181b2b66e01f057610bb51f4d40b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Laura</media:title>
		</media:content>

		<media:content url="http://laurasecurity.files.wordpress.com/2008/08/picture-4.png" medium="image" />
	</item>
		<item>
		<title>Remote IP Spoofing Attack using IP Source Routing</title>
		<link>http://laurasecurity.wordpress.com/2008/08/04/remote-ip-spoofing-attack-using-ip-source-routing/</link>
		<comments>http://laurasecurity.wordpress.com/2008/08/04/remote-ip-spoofing-attack-using-ip-source-routing/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 16:48:20 +0000</pubDate>
		<dc:creator>Laura Cristina Gheorghe</dc:creator>
				<category><![CDATA[IP Spoofing]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[IP Source Routing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://laurasecurity.wordpress.com/?p=3</guid>
		<description><![CDATA[The attacker is on a different subnet than the destionation host.
The attacker sends an IP packet with a source route specified in the IP header. This causes the destination host to send traffic back to the spoofed IP address via the route specified.

       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=laurasecurity.wordpress.com&blog=4399967&post=3&subd=laurasecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The attacker is on a different subnet than the destionation host.</p>
<p>The attacker sends an IP packet with a source route specified in the IP header. This causes the destination host to send traffic back to the spoofed IP address via the route specified.</p>
<p><a href="http://laurasecurity.files.wordpress.com/2008/08/picture-1.png"><img class="alignnone size-full wp-image-8" src="http://laurasecurity.files.wordpress.com/2008/08/picture-1.png?w=510&#038;h=259" alt="" width="510" height="259" /></a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/laurasecurity.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/laurasecurity.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/laurasecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/laurasecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/laurasecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/laurasecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/laurasecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/laurasecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/laurasecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/laurasecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/laurasecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/laurasecurity.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=laurasecurity.wordpress.com&blog=4399967&post=3&subd=laurasecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://laurasecurity.wordpress.com/2008/08/04/remote-ip-spoofing-attack-using-ip-source-routing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/763c181b2b66e01f057610bb51f4d40b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Laura</media:title>
		</media:content>

		<media:content url="http://laurasecurity.files.wordpress.com/2008/08/picture-1.png" medium="image" />
	</item>
		<item>
		<title>IP Spoofing Attack</title>
		<link>http://laurasecurity.wordpress.com/2008/08/04/ip-spoofing-attack/</link>
		<comments>http://laurasecurity.wordpress.com/2008/08/04/ip-spoofing-attack/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 16:45:01 +0000</pubDate>
		<dc:creator>Laura Cristina Gheorghe</dc:creator>
				<category><![CDATA[IP Spoofing]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TCP]]></category>

		<guid isPermaLink="false">http://laurasecurity.wordpress.com/?p=4</guid>
		<description><![CDATA[TCP Three-Way Handshake

The attacker needs to know the TCP sequence numbers used in the TCP segments so that he can send a properly constructed ACK segment to the destination. If the attacker&#8217;s ACK segment reaches the destionation before the originator&#8217;s ACK segment does, the attacker becomes trusted by destionation.

       [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=laurasecurity.wordpress.com&blog=4399967&post=4&subd=laurasecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>TCP Three-Way Handshake</p>
<p><a href="http://laurasecurity.files.wordpress.com/2008/08/picture-2.png"><img class="alignnone size-full wp-image-5" src="http://laurasecurity.files.wordpress.com/2008/08/picture-2.png?w=366&#038;h=146" alt="" width="366" height="146" /></a></p>
<p>The attacker needs to know the TCP sequence numbers used in the TCP segments so that he can send a properly constructed ACK segment to the destination. If the attacker&#8217;s ACK segment reaches the destionation before the originator&#8217;s ACK segment does, the attacker becomes trusted by destionation.</p>
<p><a href="http://laurasecurity.files.wordpress.com/2008/08/picture-3.png"><img class="alignnone size-full wp-image-6" src="http://laurasecurity.files.wordpress.com/2008/08/picture-3.png?w=444&#038;h=212" alt="" width="444" height="212" /></a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/laurasecurity.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/laurasecurity.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/laurasecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/laurasecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/laurasecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/laurasecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/laurasecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/laurasecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/laurasecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/laurasecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/laurasecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/laurasecurity.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=laurasecurity.wordpress.com&blog=4399967&post=4&subd=laurasecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://laurasecurity.wordpress.com/2008/08/04/ip-spoofing-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/763c181b2b66e01f057610bb51f4d40b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Laura</media:title>
		</media:content>

		<media:content url="http://laurasecurity.files.wordpress.com/2008/08/picture-2.png" medium="image" />

		<media:content url="http://laurasecurity.files.wordpress.com/2008/08/picture-3.png" medium="image" />
	</item>
	</channel>
</rss>