Escolar Documentos
Profissional Documentos
Cultura Documentos
INSTITUTO DE COMPUTAO
Especializao em Redes de Computadores
INF-528 GESTO DA SEGURANA DE REDES DE COMPUTADORES I
Tarefa 1
CAMPINAS SP
2014
SUMRIO
1.INTRODUO....................................................................................................................3
2.Pratica.................................................................................................................................4
2.1.Instalar Uma Ferramenta Que Permita A Injeo De Pacotes (hping, T50) Na Mquina ATACANTE
(host)............................................................................................................................................................ 4
2.2.Instalar Um Servidor Web Na Mquina ALVO........................................................................................4
2.3.Verificar O Tempo Do Download Do Index.html Desse Servidor Web A Partir Da Mquina USURIO,
1. INTRODUO
Neste laboratrio analisaremos a alterao de trafego utilizando ou no o Syn
Cookies.
Como ambiente foram utilizadas as mquinas criadas em um ambiente virtual
sendo identificado abaixo o que cada uma seria no experimento:
SP como usurio.
MS como atacante.
Mg como alvo.
2. PRATICA
2.1. Instalar Uma Ferramenta Que Permita A Injeo De Pacotes (hping, T50) Na
Mquina ATACANTE (host)
ms@ms:~$ sudo apt-get install hping3
Reading package lists... Done
Building dependency tree
Reading state information... Done
hping3 is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 134 not upgraded.
apache2-bin apache2-data
Suggested packages:
apache2-doc apache2-suexec-pristine apache2-suexec-custom apache2-utils
The following packages will be upgraded:
apache2 apache2-bin apache2-data
3 upgraded, 0 newly installed, 0 to remove and 152 not upgraded.
Need to get 1,069 kB of archives.
After this operation, 4,096 B of additional disk space will be used.
Do you want to continue? [Y/n] y
Get:1 http://us.archive.ubuntu.com/ubuntu/ trusty-updates/main apache2 i386 2.4.7-1ubuntu4.1 [87.6
kB]
Get:2
http://us.archive.ubuntu.com/ubuntu/
trusty-updates/main
apache2-bin
i386
2.4.7-1ubuntu4.1
trusty-updates/main
apache2-data
all
2.4.7-1ubuntu4.1
[821 kB]
Get:3
http://us.archive.ubuntu.com/ubuntu/
[160 kB]
Fetched 1,069 kB in 17s (62.2 kB/s)
(Reading database ... 66139 files and directories currently installed.)
Preparing to unpack .../apache2_2.4.7-1ubuntu4.1_i386.deb ...
Unpacking apache2 (2.4.7-1ubuntu4.1) over (2.4.7-1ubuntu4) ...
Preparing to unpack .../apache2-bin_2.4.7-1ubuntu4.1_i386.deb ...
Unpacking apache2-bin (2.4.7-1ubuntu4.1) over (2.4.7-1ubuntu4) ...
Preparing to unpack .../apache2-data_2.4.7-1ubuntu4.1_all.deb ...
Unpacking apache2-data (2.4.7-1ubuntu4.1) over (2.4.7-1ubuntu4) ...
Processing triggers for ureadahead (0.100.0-16) ...
ureadahead will be reprofiled on next reboot
Processing triggers for ufw (0.34~rc-0ubuntu2) ...
Processing triggers for man-db (2.6.6-1) ...
Setting up apache2-bin (2.4.7-1ubuntu4.1) ...
Setting up apache2-data (2.4.7-1ubuntu4.1) ...
Setting up apache2 (2.4.7-1ubuntu4.1) ...
* Restarting web server apache2
AH00558: apache2:
Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the
'ServerName' directive globally to suppress this message
[ OK ]
ripng-resp 3: fc00::10:10:1:0/112
ripng-req dump
08:41:42.296399
IP6
fe80::a00:27ff:fe40:5ef9.521
>
fe80::a00:27ff:fe3e:aa9.521:
ripng-resp
3:
IP
sp4.51889
>
mg4.http:
Flags
[S],
seq
2345363030,
win
29200,
options
[mss
IP
mg4.http
>
sp4.51889:
Flags
[.],
seq
1:11585,
ack
108,
win
905,
options
IP
sp4.51889
>
mg4.http:
Flags
[F.],
seq
108,
ack
Flags
[F.],
seq
11821,
11821,
win
864,
options
win
905,
options
IP
mg4.http
>
sp4.51889:
ack
109,
http://10.10.4.4/
--.-K/s
in 0.002s
used
free
shared
buffers
cached
186
162
23
30
76
-/+ buffers/cache:
Mem:
55
131
Swap:
507
507
Total:
694
162
531
CPU
top - 08:54:49 up 45 min,
Tasks:
86 total,
%Cpu(s):
0.4 us,
1 user,
1 running,
8.2 sy,
85 sleeping,
0 stopped,
0.0 wa,
0 zombie
KiB Mem:
191092 total,
184628 used,
6464 free,
KiB Swap:
520188 total,
0 used,
520188 free.
0.0 hi,
9.9 si,
0.0 st
28136 buffers
99192 cached Mem
http://10.10.4.4/
--.-K/s
in 0.001s
http://10.10.4.4/
18.3KB/s
in 0.6s
http://10.10.4.4/
--.-K/s
in 0s
http://10.10.4.4/
--.-K/s
in 0s
http://10.10.4.4/
--.-K/s
in 0s
http://10.10.4.4/
--.-K/s
in 0.001s
http://10.10.4.4/
--.-K/s
in 0.03s
http://10.10.4.4/
--.-K/s
in 0s
http://10.10.4.4/
--.-K/s
in 0.01s
http://10.10.4.4/
--.-K/s
in 0.002s
http://10.10.4.4/
10
--.-K/s
in 0.002s
87 total,
%Cpu(s):
0.6 us,
1 user,
1 running,
7.4 sy,
86 sleeping,
0 stopped,
0.0 wa,
KiB Mem:
191092 total,
184624 used,
6468 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
5.3 sy,
86 sleeping,
0 stopped,
0.0 wa,
184624 used,
6468 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
87 total,
%Cpu(s):
0.7 us,
1 running,
6.6 sy,
86 sleeping,
0 stopped,
0.0 wa,
184624 used,
6468 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
2.2 us,
1 user,
1 running,
9.4 sy,
86 sleeping,
0 stopped,
0.0 wa,
191092 total,
184708 used,
6384 free,
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
6.7 sy,
86 sleeping,
0 stopped,
0.0 wa,
184708 used,
6384 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
87 total,
%Cpu(s):
0.0 us,
2 running,
8.6 sy,
0 zombie
191092 total,
1 user,
0.0 st
28140 buffers
KiB Mem:
0 zombie
KiB Swap:
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
1 user,
0.0 st
28140 buffers
KiB Mem:
0 zombie
0.0 st
28140 buffers
99236 cached Mem
85 sleeping,
0 stopped,
0.0 wa,
0 zombie
KiB Mem:
191092 total,
184708 used,
6384 free,
KiB Swap:
520188 total,
0 used,
520188 free.
0.0 st
28140 buffers
99236 cached Mem
11
87 total,
%Cpu(s):
0.8 us,
1 user,
1 running,
4.9 sy,
86 sleeping,
0 stopped,
0.0 wa,
KiB Mem:
191092 total,
184708 used,
6384 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.8 us,
1 user,
1 running,
7.8 sy,
86 sleeping,
0 stopped,
0.0 wa,
184708 used,
6384 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
5.9 sy,
86 sleeping,
0 stopped,
0.0 wa,
191092 total,
184708 used,
6384 free,
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.6 us,
1 user,
1 running,
3.8 sy,
86 sleeping,
0 stopped,
0.0 wa,
184140 used,
6952 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
87 total,
%Cpu(s):
0.5 us,
2 running,
5.9 sy,
85 sleeping,
0 stopped,
0.0 wa,
184212 used,
6880 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
9.2 sy,
86 sleeping,
0 stopped,
0.0 wa,
191092 total,
184212 used,
6880 free,
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
7.7 sy,
86 sleeping,
0 stopped,
0.0 wa,
184208 used,
6884 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
87 total,
%Cpu(s):
0.0 us,
1 running,
5.8 sy,
0 zombie
191092 total,
1 user,
0.0 st
28140 buffers
KiB Mem:
0 zombie
KiB Swap:
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
1 user,
0.0 st
28140 buffers
KiB Mem:
0 zombie
KiB Swap:
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
0.0 st
28140 buffers
99236 cached Mem
86 sleeping,
0 stopped,
0.0 wa,
0 zombie
KiB Mem:
191092 total,
184224 used,
6868 free,
KiB Swap:
520188 total,
0 used,
520188 free.
0.0 st
28140 buffers
99236 cached Mem
12
87 total,
%Cpu(s):
1.2 us,
1 user,
2 running,
6.8 sy,
85 sleeping,
0 stopped,
0.0 wa,
KiB Mem:
191092 total,
184256 used,
6836 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
7.6 sy,
86 sleeping,
0 stopped,
0.0 wa,
184288 used,
6804 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
87 total,
%Cpu(s):
0.0 us,
1 running,
5.4 sy,
86 sleeping,
0 stopped,
0.6 wa,
184288 used,
6804 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
6.0 sy,
86 sleeping,
0 stopped,
0.0 wa,
191092 total,
184288 used,
6804 free,
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
6.3 sy,
86 sleeping,
0 stopped,
0.0 wa,
184288 used,
6804 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
87 total,
%Cpu(s):
1 running,
86 sleeping,
0 stopped,
0.0 wa,
184304 used,
6788 free,
KiB Swap:
520188 total,
0 used,
520188 free.
87 total,
%Cpu(s):
0.0 us,
1 user,
1 running,
4.4 sy,
0 zombie
191092 total,
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
1 user,
0.0 st
28140 buffers
KiB Mem:
0 zombie
KiB Swap:
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
Tasks:
0.0 st
28140 buffers
KiB Mem:
0 zombie
191092 total,
1 user,
0.0 st
28140 buffers
KiB Mem:
0 zombie
0.0 st
28140 buffers
99236 cached Mem
86 sleeping,
0 stopped,
0.0 wa,
0 zombie
KiB Mem:
191092 total,
184304 used,
6788 free,
KiB Swap:
520188 total,
0 used,
520188 free.
0.0 st
28140 buffers
99236 cached Mem
2.7. Questes
O tempo de acesso ao servidor Web muda? (Ref. o item 3).
Tempo de acesso tem uma ocilacao sim devido a injeo de pacotes.
13
IP
sp2.ssh
>
ms3.59642:
Flags
[P.],
seq
1480:1680,
ack
27,
win
453,
options
ripng-req dump
IP6
fe80::a00:27ff:fe40:5ef9.521
>
fe80::a00:27ff:fe3e:aa9.521:
ripng-resp
3:
14
IP
sp4.51909
>
mg4.http:
Flags
[S],
seq
3716617581,
win
29200,
options
[mss
IP
mg4.http
>
sp4.51909:
Flags
[P.],
seq
1:11821,
ack
108,
win
905,
options
IP
sp4.51909
>
mg4.http:
Flags
[F.],
seq
108,
ack
[F.],
seq
11821,
11821,
win
826,
options
win
905,
options
IP
mg4.http
>
sp4.51909:
Flags
ack
109,
ripng-resp 3: fc00::10:10:1:0/112
http://10.10.4.4/
--.-K/s
in 0.001s
15
used
free
shared
buffers
cached
186
181
17
98
-/+ buffers/cache:
Mem:
66
120
Swap:
507
507
Total:
694
181
513
CPU
top - 10:11:02 up
Tasks:
92 total,
%Cpu(s):
0.6 us,
2:02,
3 users,
2 running,
5.2 sy,
90 sleeping,
0 stopped,
0.6 wa,
0 zombie
KiB Mem:
191092 total,
185784 used,
5308 free,
KiB Swap:
520188 total,
0 used,
520188 free.
0.0 hi,
6.0 si,
0.0 st
17532 buffers
100396 cached Mem
Testar a ferramenta de injeo de pacotes contra a mquina ALVO a partir da mquina ATACANTE.
ms@ms:~$ sudo hping3 -V -c 20 -d 60 -S -w 64 -p 80 --flood --rand-source 10.10.4.4
using eth2, addr: 10.10.3.2, MTU: 1500
HPING 10.10.4.4 (eth2 10.10.4.4): S set, 40 headers + 60 data bytes
hping in flood mode, no replies will be shown
^C
--- 10.10.4.4 hping statistic --9086 packets transmitted, 0 packets received, 100% packet loss
round-trip min/avg/max = 0.0/0.0/0.0 ms
ms@ms:~$
http://10.10.4.4/
--.-K/s
in 0.001s
http://10.10.4.4/
16
100%[======================================>] 11,510
--.-K/s
in 0.006s
http://10.10.4.4/
--.-K/s
in 0s
http://10.10.4.4/
--.-K/s
in 0.002s
92 total,
%Cpu(s):
0.6 us,
2:15,
3 users,
1 running,
5.2 sy,
91 sleeping,
0 stopped,
0.6 wa,
KiB Mem:
191092 total,
182148 used,
8944 free,
KiB Swap:
520188 total,
0 used,
520188 free.
top - 10:24:04 up
Tasks:
92 total,
%Cpu(s):
0.6 us,
2:15,
3 users,
3 running,
7.7 sy,
89 sleeping,
0 stopped,
0.0 wa,
182148 used,
8944 free,
520188 total,
0 used,
520188 free.
%Cpu(s):
0.0 us,
2:15,
3 users,
1 running,
6.3 sy,
91 sleeping,
0 stopped,
0.0 wa,
182212 used,
8880 free,
KiB Swap:
520188 total,
0 used,
520188 free.
Tasks:
92 total,
3 users,
1 running,
0 zombie
191092 total,
2:15,
0.0 st
16800 buffers
KiB Mem:
top - 10:24:10 up
0 zombie
191092 total,
92 total,
0.0 st
KiB Swap:
Tasks:
6.1 si,
16800 buffers
KiB Mem:
top - 10:24:07 up
0 zombie
0.0 hi,
0.0 st
16800 buffers
97488 cached Mem
91 sleeping,
0 stopped,
0 zombie
17
%Cpu(s):
0.7 us,
6.0 sy,
0.0 wa,
191092 total,
182240 used,
8852 free,
KiB Swap:
520188 total,
0 used,
520188 free.
KiB Mem:
0.0 st
16808 buffers
97492 cached Mem
mg@mg:~$
18