A1: Spoofer

Assignment Series #A1 Spoofer

Compile your first Software in Linux (caida spoofer tool)

1. Task description

The receipt of compiling a software with automake is mostly the same:

gzip -d project.tar.gz
tar -xvf project.tar
cd project
configure --prefix=/opt/applic/project
make
make install

After you’ve downloaded, built and run the spoofer tool from scratch, please start wireshark and answer the following questions:

  1. Explain the idea of ip spoofing
  2. Is this a realistic attack over the internet with TCP/IP – explain
  3. Is this a realistic attack over the internet with UDP/IP – explain
  4. What are the destination addresses of the spoofer tool (see in Wireshark)
  5. What protocol is the spoofer tool trying to spoof?
  6. Do you find your own results on https://spoofer.caida.org/recent_tests.php

2. Answers

  1. The idea behind IP spoofing is the creation of Internet Protocol (IP) packets which have a modified source address in order to either hide the identity of the sender, to impersonate another computer system, or both. It is a technique often used by bad actors to invoke DDoS attacks against a target device or the surrounding infrastructure.
  2. Not really. Direct access to traffic is now much more difficult if the intruder’s computer is not on the same subnet. This is due to the fact that intercepting a data packet is only possible with the help of the corresponding packet sequence number – a task that is almost impossible today compared to earlier days from outside.
    In the past, operating systems and network devices still generated these process numbers entered in the TCP header according to a pattern that was always the same. As today’s systems output the sequence numbers randomly, these so-called TCP sequence prediction attacks (also called blind spoofing) have basically become ineffective – however, older devices are still at risk.
  3. I’d say yes, becuase UDP doesn’t use a three way handshake or any sequence numbers to establish a connection.
  4. The spoofer tool communicates with the ip address 192.172.226.242

    In Wireshark it looks like this (filter ip.dst == 192.172.226.242)

    To get a list of all destination addresses I use the Statistics –> Coversations menu:

  5. It’s the UDP Protocol. The methodology says:

The spoofer program attempts to send a series of spoofed UDP packets to servers distributed throughout the world. These packets are designed to test:

  • Different classes of spoofed IPv4 and IPv6 addresses, including private and routable
  • Ability to spoof neighboring, adjacent addresses
  • Ability to spoof inbound (towards the client) and outbound (from the client)
  • Where along the path filtering is observed
  • Presence of a NAT device along the path
  1. Yes. https://spoofer.caida.org/report.php?sessionid=1014179

PDF Report
Spoofer#1