In NDP Man-in-the-Middle (MitM) attacks, which action is used to intercept traffic?

Enhance your skills with the GCIA Traffic Analysis Test. Prepare with insightful questions and detailed explanations. Excel in your exam!

Multiple Choice

In NDP Man-in-the-Middle (MitM) attacks, which action is used to intercept traffic?

Explanation:
Router Advertisements establish where hosts send their traffic beyond the local link by setting the default gateway. A attacker on the same IPv6 link can send counterfeit Router Advertisements that appear to come from a legitimate router, causing hosts to install the attacker’s device as their default gateway. Once that happens, the attacker sits on the path between hosts and the wider network, so traffic flows through the attacker and can be intercepted or altered. Other ND spoofing tricks, like faking a Neighbor Advertisement to tie an address to the wrong MAC or spoofing requests for non-existent addresses, can disrupt or confuse neighbor caches but don’t routinely reroute all traffic through the attacker. Thus, spoofing a Router Advertisement to redirect traffic is the mechanism that enables a man-in-the-middle position in NDP.

Router Advertisements establish where hosts send their traffic beyond the local link by setting the default gateway. A attacker on the same IPv6 link can send counterfeit Router Advertisements that appear to come from a legitimate router, causing hosts to install the attacker’s device as their default gateway. Once that happens, the attacker sits on the path between hosts and the wider network, so traffic flows through the attacker and can be intercepted or altered. Other ND spoofing tricks, like faking a Neighbor Advertisement to tie an address to the wrong MAC or spoofing requests for non-existent addresses, can disrupt or confuse neighbor caches but don’t routinely reroute all traffic through the attacker. Thus, spoofing a Router Advertisement to redirect traffic is the mechanism that enables a man-in-the-middle position in NDP.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy