ARP

    ARP(Address Resolution Protocol)

    1. ARP(Address Resolution Protocol) - ๊ฐ™์€ ๋„คํŠธ์›Œํฌ ์•ˆ์—์„œ ํŠน์ • IP ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง„ MAC ์ฃผ์†Œ๋ฅผ ์•Œ์•„๋‚ด์–ด L2 ํ†ต์‹ ์„ ํ•˜๊ธฐ ์œ„ํ•จ - ๋„คํŠธ์›Œํฌ ํ†ต์‹ ์€ IP ์ฃผ์†Œ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋ฉฐ Destination IP ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  L3 ์˜์—ญ๊นŒ์ง€ ๋„์ฐฉํ•˜๊ณ  L2 ์Šค์œ„์น˜๋ฅผ ํ†ตํ•˜์—ฌ MAC ์ฃผ์†Œ๋ฅผ ์•Œ์•„๋‚ด์–ด L2 End to End ํ†ต์‹ ์„ ํ•จ - ๋ฌด์„  AP๊ฐ€ ํŠน์ • IP ์ฃผ์†Œ์˜ MAC ์ฃผ์†Œ๋ฅผ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•˜์—ฌ Broadcast๋กœ ARP Reqeust(Who has ํŠน์ • IP?) - ํŠน์ • IP๋ฅผ ๊ฐ€์ง„ ์žฅ๋น„๊ฐ€ ๋ฌด์„  AP๋กœ MAC ์ฃผ์†Œ Unicast๋กœ ARP Reply(ํŠน์ • IP is at MAC ์ฃผ์†Œ) - ์‹ค์ œ 192.168.219.194 IP ์ฃผ์†Œ๊ฐ€ 90:9c:4a:c8:a4:44 MAC ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  ..

    ARP Spoofing

    ARP Spoofing - Client IP ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  MAC ์ฃผ์†Œ๋ฅผ ์ฐพ์•„๋‚ด๋Š” ๋ฐฉ๋ฒ• - ARP Request : ARP ํ…Œ์ด๋ธ”์— IP ์ฃผ์†Œ๊ฐ€ ์—†๋‹ค๋ฉด ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ๋ฅผ ํ†ตํ•ด IP ์ฃผ์†Œ๋ฅผ ์•Œ์•„๋‚ด MAC ์ฃผ์†Œ ์š”์ฒญ - ARP Response : Request๋ฅผ ์ˆ˜์‹ ํ•œ Client๋Š” IP ์ฃผ์†Œ๊ฐ€ ์ž์‹ ์˜ IP ์ฃผ์†Œ์ผ ๊ฒฝ์šฐ MAC ์ฃผ์†Œ ์‘๋‹ต - ARP ํ…Œ์ด๋ธ”์€ ์ตœ๊ทผ Response ์—…๋ฐ์ดํŠธ(์ธ์ฆ ์—†์Œ, ์ทจ์•ฝ์ ) - LAN์—์„œ ์˜จ๋ผ์ธ์œผ๋กœ ํ™•์ธ๋˜์ง€ ์•Š์œผ๋ฉด ARP ํ…Œ์ด๋ธ”์—์„œ ์‚ญ์ œ(์ฃผ๊ธฐ์ ์œผ๋กœ Spoofing Packet์„ ๋ณด๋‚ด์•ผ ํ•จ) - Linux/Windows๋Š” 120์ดˆ ํ˜น์€ ์ด์ƒ์ด์ง€๋งŒ 40์ดˆ๊ฐ€ ๊ฐ€์žฅ ์ ๋‹น - Client ARP ํ…Œ์ด๋ธ” ์œ„์กฐ ๋Œ€์ฑ… - ํŒจํ‚ท ๋ถ„์„์„ ํ†ตํ•ด ARP Storm์ด ์žˆ๋Š”์ง€ ํ™•์ธ - IP ์ฃผ์†Œ์™€ MA..