Thursday, February 12, 2015

Common TCP/IP Protocols

Logical Address:

  • The internetwork address of a machine.
  • It is unique universally ( for a local network, universe is the small local network)
  • It is implemented in software.
  • IP address is the logical address in TCP/IP protocol suite.
Physical Address:
  • At physical level, a host or a router is recognized by its Physical address
  • Physical address is useful only in local network.
  • It has to be unique locally but doesn't need to be unique universally.
  • It is usually ( but not always) implemented in HARDWARE.
  • MAC address is a physical address.

Static Mapping:

  • To create a table containing the IP to MAC address mapping.
  • Table is stored on each machine on the network.
  • Limitation: Physical address of a machine may change for many reasons.
  • Limitation: Static mapped table has to be updated periodically.
Dynamic Mapping:
  • Using ARP, RARP to find either the IP or the MAC address of a machine.

ARP (Address Resolution Protocol)




  • If sender has the local IP address, and needs to know the Physical address to send a packet in local network, it uses ARP protocol.
  • ARP is used for dynamic mapping.
  • Maps LOGICAL ADDRESS to PHYSICAL ADDRESS.
  • ARP packet contains the (IP, MAC) of sender and (IP) of receiver, and is sent to BROADCAST address FF:FF:FF:FF:FF:FF ( all 1s). 
  • All hosts receive the packet but only the intended recipient recognizes the IP address and sends back an ARP Response Packet. The response is UNICAST only to the ENQUIRER. 
  • ARP request is Broadcast & ARP response is UNICAST.
RARP ( Reverse Address resolution Protocol)
  • Dynamically Maps PHYSICAL address to LOGICAL ADDRESS
  • When a DISKLESS machine wants to get its OWN LOGICAL address after a reboot, it sends a RARP to BROADCAST FF:FF:FF:FF:FF:FF ( all 1s) address.
  • Response is sent by the RARP SERVER as UNICAST.
  • Alternatives to RARP: BOOTP & DHCP ( provides additional info like subnet mask also)
  • RARP Server does not provide info like subnet mask, which is required by a diskless host.
WHAT IS ARP Spoofing?

  • ARP spoofing or ARP cache poisoning is a technique by which an attacker sends (spoofed) Address Resolution Protocol (ARP) messages onto a local area network. 
  • The aim is to associate the attacker's MAC address with the IP address of another host, such as the default gateway, causing any traffic meant for that IP address to be sent to the attacker instead. 
  • The attack can only be used on networks that use the Address Resolution Protocol
  • ARP Spoofing can be used for DoS & MITM attacks.
Prevention?

IP Protocol

  • Connection-less, Unreliable , best effort delivery service.
  • Provides addressing and routing capabilities for each data packet.
  • Used as transmission mechanism by TCP/IP Protocol. 
  • Data is packed in a Datagram
  • Datagrams can take different routes and arrive out of order.
  • Datagrams might be duplicated.
  • Doesn't keep track of route.
  • Doesn't order the packets.
ICMP: INTERNET CONTROL MESSAGE PROTOCOL
  • IP protocol lacks the ability to report errors & to check if a particular host is alive.
  • ICMP compensates for the lack of error control & query facilities in IP protocol.
  • ICMP  is a companion of IP protocol.
  • ICMP protocol is a Transport layer protocol, but its packets are not directly sent to the Data Link Layer. They are first encapsulated INSIDE an IP datagram.
ICMP Error Reporting
  • ICMP always reports errors to the original Source ONLY.
  • ICMP error message will NEVER be responsed with an ICMP error message
  • ICMP error message is NOT generated for a datagram with MULTICAST Address.
  • ICMP error message will NOT be generated for a special IP address ( 127.0.0.1, 0.0.0.0)
  • Destination Unreachable: ICMP message is generated in response to destination(host or protocol or port) unreachable. 
  • Source Quench : ICMP message is generated if there Congestion at the router or destination, slow down babe! (Sender)
  • Time Exceeded
  • Parameter Problem ( ambiguity or missing field in datagram)
  • Redirection: Host's (non-router) routing table is updated statically. A method of updating the routing table is to send the packet to wrong router. It will be redirected to the correct router and an ICMP message will be sent to the host to update its routing table.
ICMP for Diagnostic purposes

Echo-request & echo-reply ICMP messages: 
  • Used to check if the host is able to communicate with the destination host or router.
  • Used to check if intermediate routers are working.
  • Used to check if IP protocols on source & destination are working properly.
  • Echo-request is sent by the Sender.
  • Echo-reply is sent by the destination.
Time stamp request & time-stamp reply ICMP messages:
  • Used to calculate the round-trip time between source & destination even if their clocks are not synchronized.
Address mask request & Reply ICMP messages:
  • Used to find out host's own address mask from a router.
  • May be used in combination with RARP(to find IP) in case of diskless hosts.
How does Ping work? PING - Packet internet groper command.
  • Ping is a network utility which can generate a series of ICMP echo-request & echo reply messages to test the reachability of a host. 
  • It also provides statistical information about RoundTrip time by sending its own time stamp in the optional data section of the ICMP echo-request & echo reply message.
  • Ping program has to be stopped using CTRL+C otherwise it goes on.
  • Ping prints - TTL, packet loss, number of packets sent, number of packets received etc.
  • TTL part of the Ping command = number of maximum hops allowed
How does traceroute (UNIX) work
  • Traceroute is used to trace the route of a packet from source to destination. 
  • Traceroute uses two error messages - TIME EXCEEDED & Destination Unreachable 
  • Traceroute program sends an IP packet using UDP (destined to the wrong port). 
  • The TTL of the IP packet is incrementally set to 1,2,3,4,5 until the destination is reached. 
  • Each router on the path to the destination will decrement the TTL and whenever TTL 0 is reached the router will send back an ICMP "Time Exceeded" error message along with its own IP address. 
  • Traceroute also calculates the round trip time for each of these intermediate routers
  • In each of these messages the UDP packet is sent to a port that is not supported by UDP. When the packet reaches the destination and TTL=0 it WILL NOT throw a "Time exceeded" error. However, the destination host sends an ICMP "Destination Unreachable" packet, because the port number is wrong. This error message indicates that the destination has been reached.

5 comments:

  1. ACTIVE & FRESH CC FULLZ WITH BALANCE
    Price $5 per each CC

    US FRESH, TESTED & VERIFIED SSN LEADS
    $1 PER EACH

    *Time wasters or cheap questioners please stay away
    *You can buy for your specific states too
    *Payment in advance

    CC DETAILS
    =>CARD TYPE
    =>FIRST NAME & LAST NAME
    =>CC NUMBER
    =>EXPIRY DATE
    =>CVV
    =>FULL ADDRESS (ZIP CODE, CITY/TOWN, STATE)
    =>PHONE NUMBER,DOB,SSN
    =>MOTHER'S MAIDEN NAME
    =>VERIFIED BY VISA
    =>CVV2

    SSN LEADS INFO
    First Name | Last Name | SSN | Dob | Address | State | City | Zip | Phone Number | Account Number | Bank NAME | DL Number | Home Owner | IP Address |MMN | Income

    Contact Us

    -->Whatsapp > +923172721122
    -->Email > leads.sellers1212@gmail.com
    -->Telegram > @leadsupplier
    -->ICQ > 752822040

    *Hope for the long term deal
    *If you buy leads in bulk, I'll definitely negotiate
    *You can ask me for sample of Lead for demo

    US DUMP TRACK 1 & 2 WITH PIN CODES ALSO AVAILABLE

    ReplyDelete
  2. Telegram= @leadsupplier @killhacks @jacobfullz
    ICQ= 752822040 / @killhacks
    Email= hacksp007 @ dnmx.org

    FRESH FULLZ/PROS AVAILABLE

    CC with CVV
    SSN DOB DL
    High Credit Scores Pros
    Business EIN Fullz
    Dumps with PIN Codes Track 101 & 202
    DL Scan Front & Back
    Fullz for KYC, PUA, UI, Tax Refund

    USA, UK, CANADA Fullz Available
    Fresh & Legit stuff
    No refund only replacement

    ReplyDelete
  3. Hello Everyone !

    If you're in searching of Legit & Fresh Fullz..
    You're at RIGHT PLACE

    Providing Fresh Spammed UPDATED 2023 Fullz with guarantee
    Stuff will be genuine & Legit (replace if found invalid)
    Many Countries Fullz Available
    USA|UK|CANADA|RU|AUS|FR|ASIA

    <-Feel Free To Contact Us & Enjoy->
    ---------------------------------
    ICQ> 752822040 | @killhacks
    Telegram> @killhacks | @leadsupplier
    Skype|WICKR> @peeterhacks
    Email> hacksp007 @ DNMX.org
    WhatsApp> (On Demand)

    =============
    FULLZ LIST
    =============
    SSN DOB DL ADDRESS FULLZ====================2$ Each (Min Qty 25)
    SIN DOB ADDRESS FULLZ (CANADA)==============1.5$ Each (Min Qty 25)
    CC FULLZ WITH CVV & BILLING ADDRESS=========8$ Each (Min Qty 5)
    HIGH CREDIT SCORES PROS (700+ Credit)=======5$ Each (Min Qty 10)
    DL/ID SCAN FRONT & BACK WITH SELFIE & SSN (ALL USA STATES)======25$ Each
    BUSINESS EIN COMPANY FULLZ=====12$ Each
    SPECIFIC FULLZ (GENDER|CITY|STATE|AGE)====2.5$ Each (Min Qty 25)
    BULK FULLZ (USA|CANADA|UK)
    PUA|UI|KYC|TAX RETURN FILLING FULLZ
    CLONING DUMPS CARD WITH PIN (TRACK 101&202)=======75$ Each
    YOUNG AGE FULLZ (2002 ABOVE)=============2$ Each (Min Qty 25)
    FULLZ WITH CURRENT EMPLOYEE & BANK DETAILS=======2$ Each (Min Qty 25)

    (USA)
    Name + SSN + Dob + DL|ID Number + Address + Phone + Email + Work Info + Bank Info
    claudia|gonzalez|567850156|10.04.1985|d3150237|335Dorisave|OXNARD|CA|93030|8056519095|8056519095|littleone0704@yahoo.com|cabrilloradiation|8056485133|VENTURACOUNTYCREDIT|144210|322283505

    (CANADA)
    NAME + ADDRESS + CITY + STATE + COUNTRY + DOB + SIN + PHONE + MMN + ZIPCODE
    KARINE BEAUDOIN|590 RUE PRINCIPALE|ST/THEOPHILE|QUEBEC|CA|1977/06/12|276-116-449|4182227484|LAMBERT|G0M 2A0

    CC Number + Expmm + Expyyyy + CVV + Name + Address + Country + SSN + DOB + Phone
    4610460213146269|07|24|914|Sydney Cutsail|9000 Tate Avenue|76244|Keller|Texas|United States|636-52-0685|04/06/1996|9034951145

    Many other stuff available regarding Fullz & Tools
    Payment Mode BTC|USDT|ETH (Preferable) or any Crypto payment accepted
    No sampling for CC's & DL|ID Scans
    Payment Upfront
    Stuff will be provided within few mins after payment proof
    Testing will be for bulk buyers only
    ***********************************************************************

    TOOLS|TUTORIALS|METHODS|CLONING|SCRIPTING|SCAM-PAGES

    All HACKING|SPAMMING|CARDING|SCRIPTING Tools are Available
    Including all tutorials & E-books
    Updated Loan Methods & Carding Methods

    TOOLS LIST
    -SMTP|RDP
    -SHELLS|C-PANELS
    -WEB MAILERS
    -BRUTES
    -MAILERS|SENDERS|BOMBERS
    -CC CHECKER|CC VALIDATOR
    -SMTP LINUX ROOT
    -SCAM PAGES|SCAM PAGE SCRIPTING
    -LOAN|ATM CARD METHODS
    -CLONING TUTORIALS
    -OFFICE365 LEADS|LOGINS|SMTPS

    Valid & Genuine Tools will be provided with guarantee
    Fresh Tools & Tutorials on demand with updates
    Hacking|Spamming|Carding Packages are available too
    No testing for Tools

    Here we're:
    -------------------------------------
    ICQ> 752822040 | @killhacks
    Telegram> @killhacks | @leadsupplier
    Skype|WICKR> @peeterhacks
    Email> hacksp007 @ DNMX.org
    WhatsApp> (On Demand)

    Just Try Our Stuff
    It will Never Disappoint You Guy's
    Come & Join US to Make A GooD Money

    ReplyDelete
  4. UPDATED FRESH FULLZ DEC-2023
    USA UK CANADA
    VALID & FRESH WITH GUARANTEED RESULTS
    ALL INFO VERIFIED & CHECKED

    SSN DOB DL ADDRESS FULLZ
    SIN DOB ADDRESS FULLZ
    NIN DOB DL ADDRESS FULLZ
    REAL ID/DL SCAN FRONT BACK WITH SELFIE
    HIGH CREDIT SCORES PROS
    BUSINESS EIN COMPANY FULLZ
    YOUNG AGE FULLZ
    CC CVV WITH BILLING ADDRESS
    CLONING DUMPS CARD TRACK 101 & 202 WITH PIN CODES
    FULL FOR TAX-RETURN|UI|PUA|SBA|UBEREATS|DOORDASH|KYC
    OFFICE365 LEADS|LOGINS
    SMTP'S|RDP|C-PANELS|SHELLS|WEB-MAILERS

    Tutorials are also available for
    Carding|Spamming|Scripting|Cash-out|Loan Methods

    Genuine stuff will be provided
    No scam, if anything found invalid will replace
    Limited Stock available

    Contact Fast

    ICQ 752822040 | @killhacks
    Telegram @leadsupplier | @killhacks
    Email bigbull0334 @ onion mail . org
    Skype @peeterhacks

    ReplyDelete