Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Sniffing attack

From Wikipedia, the free encyclopedia
Theft of data by using a packet sniffer

Sniffing attack in context ofnetwork security, corresponds totheft or interception of data by capturing thenetwork traffic using apacket sniffer (an application aimed at capturingnetwork packets). When data is transmitted across networks, if the data packets are not encrypted, the data within the network packet can be read using a sniffer.[1] Using a sniffer application, an attacker can analyze the network and gain information to eventually cause the network to crash or to become corrupted, or read the communications happening across the network.[2]

General

[edit]

Sniffing attacks can be compared totapping of phone wires and intercepting the conversation. For this reason, it is also referred aswiretapping applied tocomputer networks. Using sniffing tools, attackers can sniff sensitive information from a network, includingemail (SMTP, POP, IMAP),web (HTTP),FTP (Telnet authentication, FTP Passwords, SMB, NFS) and many more types ofnetwork traffic. The packet sniffer usually sniffs the network data without making any modifications in the network's packets. Packet sniffers can just watch, display, and log the traffic, and this information can be accessed by the attacker.[3]

Prevention

[edit]

To prevent networks from sniffing attacks, organizations and individual users should keep away from applications that are using insecure protocols, likebasic HTTP authentication, File Transfer Protocol (FTP), andTelnet. Instead, secure protocols such asHTTPS,Secure File Transfer Protocol (SFTP), andSecure Shell (SSH) should be preferred. In case there is a necessity for using any insecure protocol in any application, all the data transmission should be encrypted. If required,VPN (Virtual Private Networks) can be used to provide secure access to users.[4]

See also

[edit]

References

[edit]
  1. ^"Types of attacks - Sniffer Attack".Omnisecu.com. OmniSecu. Retrieved11 September 2017.
  2. ^"Common Types of Network Attacks".Technet.microsoft.com. Microsoft. 18 July 2012. Retrieved11 September 2017.
  3. ^"Packet sniffing".Colasoft.com. Colasoft. Retrieved11 September 2017.
  4. ^"What is a Wireless Sniffer?".Veracode.com. Veracode. Retrieved11 September 2017.
Retrieved from "https://en.wikipedia.org/w/index.php?title=Sniffing_attack&oldid=1323262131"
Category:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp