During an NDP Man-in-the-Middle attack, spoofing which message causes traffic to be redirected to the attacker?

Enhance your skills with the GCIA Traffic Analysis Test. Prepare with insightful questions and detailed explanations. Excel in your exam!

Multiple Choice

During an NDP Man-in-the-Middle attack, spoofing which message causes traffic to be redirected to the attacker?

Explanation:
In IPv6, the router discovery process uses Router Advertisements to tell a host which router to use as its default gateway. If an attacker can spoof these advertisements, the host may accept the attacker’s router as its default gateway. That means all of the host’s traffic is sent to the attacker first, who can then forward it on to its real destination or inspect/modify it along the way. Spoofing Router Advertisements thus directly redirects the host’s traffic through the attacker, enabling a Man-in-the-Middle position. (Notes: Redirect messages exist to tell a host of a better route for a specific destination, but spoofed rogue Router Advertisements gain control of the default route for the entire traffic flow, which is why this method is commonly cited for MITM in ND contexts.)

In IPv6, the router discovery process uses Router Advertisements to tell a host which router to use as its default gateway. If an attacker can spoof these advertisements, the host may accept the attacker’s router as its default gateway. That means all of the host’s traffic is sent to the attacker first, who can then forward it on to its real destination or inspect/modify it along the way. Spoofing Router Advertisements thus directly redirects the host’s traffic through the attacker, enabling a Man-in-the-Middle position.

(Notes: Redirect messages exist to tell a host of a better route for a specific destination, but spoofed rogue Router Advertisements gain control of the default route for the entire traffic flow, which is why this method is commonly cited for MITM in ND contexts.)

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy