Rogue DHCP Server | Man-in-the-Middle Attack

Поділитися
Вставка
  • Опубліковано 2 жов 2024

КОМЕНТАРІ • 84

  • @MrAwesomenesh
    @MrAwesomenesh 3 роки тому +12

    You guys rock! This channel has seriously helped my fundamental knowledge as I prepare for higher certs. I love the perspective you guys attack each subject with.

    • @Certbros
      @Certbros  2 роки тому +1

      Wow thanks! Really appreciate it!

  • @MrArnipress
    @MrArnipress 2 роки тому +1

    It saddens me that such an amazing content has such a little views. Deserves way more than that.

  • @mrgigs08
    @mrgigs08 Рік тому +1

    Like I said, you guys are amazing! F**** Bombal that guy is drilling my brains just in vain. That is what I call explanation I mean yours of course! great job guys!

  • @WeBBerTutoriais
    @WeBBerTutoriais 3 роки тому +2

    Very Good!! Brazil!

    • @Certbros
      @Certbros  3 роки тому +1

      Thank you! I would love to visit Brazil one day!

  • @ishmaelvaughn9110
    @ishmaelvaughn9110 2 роки тому +3

    I come to you guys any time I do not understand a networking concept, and every time you guys make it easier and visible for me to understand. Content goes crazy thank you!

    • @Certbros
      @Certbros  2 роки тому

      Thank you Ishmael! Really great to hear the videos are helping. Hope to have more for you very soon!

  • @mani_logs
    @mani_logs 2 місяці тому

    Very nice for learning❤but i think i'ts better to say: IF WEBSITE HAVE (HTTPS) AND SSL OR TSL VERIFICATION, WE CAN'T USE MITM ATTACK. Thanks

  • @BiMathAx
    @BiMathAx 2 роки тому +2

    You need more than 300 likes...

    • @Certbros
      @Certbros  2 роки тому +1

      Thanks! I'll give you a like for the comment 😀

  • @erwindee7384
    @erwindee7384 3 роки тому +1

    I know HTTPS protects against this very effectively, but is there any way to make sure that I'm connecting to the right DHCP server when, say, I connect to public Wi-Fi? Let's say I didn't connect to some hacker's Wi-Fi network and I really am on some legitimate coffee shop's Wi-Fi network. How do I make sure I'm getting DHCP from the coffee shop's router?

    • @laplongejunior
      @laplongejunior 3 роки тому

      I think you can't as DHCP is broadcast based and there's no reason to assume the DHCP would be on the router.
      In my own lan, the router's DHCP is for static configuration only and unknown clients are issued IPs by my Pihole

  • @BugsVsHumans
    @BugsVsHumans Рік тому

    Hi how can you stop rogue dhcp server from a network? How do you configure the router to stop it?

  • @wildyato3737
    @wildyato3737 2 роки тому

    Now don't trust router....and get fcking Cellular connection..

  • @sadeeshkumar654
    @sadeeshkumar654 3 роки тому +3

    Brilliant content. Thank you

    • @Certbros
      @Certbros  3 роки тому

      Thank you Sadeesh!

  • @di0r
    @di0r 5 місяців тому

    Actually very good video. Subbed

  • @alurma
    @alurma 3 роки тому +1

    Thanks

    • @Certbros
      @Certbros  3 роки тому

      You're welcome Vasya!

  • @LoneWolf137
    @LoneWolf137 3 роки тому +2

    Thanks for your hard work! Awesome video!!!

    • @Certbros
      @Certbros  3 роки тому

      Thanks! Happy to hear you liked it. These comments make the work worth it 👌

  • @jaydenritchie1992
    @jaydenritchie1992 Рік тому

    so wifi connection or lan vpn or pppoe logon would eliminate this?

  • @kevorka3281
    @kevorka3281 Рік тому +1

    What's a rooter

  • @M3nt4LC4t
    @M3nt4LC4t 3 роки тому +1

    off topic. what about phishing websites that are using https? how the scammer obtain users' credential?

    • @Certbros
      @Certbros  3 роки тому +2

      Great question! It's now common for phishing sites to use HTTPS. Because the bad guys own the websites, they are able to see what credentials are being inputed by the victim.

  • @undeadhero9141
    @undeadhero9141 2 роки тому

    so how do i stop this please??

  • @TheGodOfAllThatWas
    @TheGodOfAllThatWas Рік тому

    A rogue DHCP server doesn't even have to be a MITM attack to be a headache..... Things like wireless AP's and some NAS devices can be misconfigured to run DHCP to an internet connection they don't have and cause all kinds of weird headaches. It's especially annoying if the Flash memory it uses for booting is starting to go out and it resets itself to default on occasion, when the default is DHCP to be on, and it's not connected in a manor to handle WAN traffic. Suddenly people get Duplicate IP messages, or can access the LAN but not the internet, or some people can't access anything but others are fine..... And then it goes away when you show up to fix it.... To only come back in a day or two..... The duplicate IP thing is kind of a dead give away, but beyond that it can be a big headache to troubleshoot since like mentioned in the video it's pretty random when your computer will decide it'll take a new IP address.

  • @Best_Blockchan_Builders
    @Best_Blockchan_Builders 3 роки тому +3

    What is the difference between app poisoning and this?

    • @Certbros
      @Certbros  3 роки тому +3

      I assume you mean ARP Poisoning. The outcome is very similar but the way we achieve it is different.
      Rogue DHCP / DHCP spoofing requires the attacker to assign malicious IP address information by taking the role of a DHCP server. ARP poisoning requires the attacker to send false information to the network and pretend to be someone he is not.

    • @Best_Blockchan_Builders
      @Best_Blockchan_Builders 3 роки тому +2

      @@Certbros Thank you for the explanation

    • @Certbros
      @Certbros  3 роки тому +1

      No problem Alexander! Happy to help 👍

  • @espionn
    @espionn 3 роки тому +1

    You missed the word 'snooping' in the description :)

    • @Certbros
      @Certbros  3 роки тому

      Great spot! Thank you 😁

  • @vladislavkaras491
    @vladislavkaras491 2 роки тому

    Great video!
    Thanks for practical demonstration of how it looks and how it works!
    I do have a question. When I connect to http (and maybe even https) through the hacker's PC, do I leave such things as cookies, and similiar stuff, that can be used instead of login credintials?
    Thanks for the video!

    • @TheGodOfAllThatWas
      @TheGodOfAllThatWas Рік тому +1

      Webserver tells your computer to set a cookie.... Your computer can then potentially send the data in the cookie instead of the using a user name and password. On a non-encrypted connection the hackers PC would see that information (either the instruction from the server to set the cookie, or your computer saying Hey use this cookie) and be able to record the cookies used. I assume there's a tool a hacker could use, but worse case Wireshark would show the raw data. So you wouldn't "Leave" the cookies, but you'd allow the hacker to scan the cookie and recreate it. Like mentioned in the video encryption (Https, or a vpn) would stop this.

    • @vladislavkaras491
      @vladislavkaras491 Рік тому

      @@TheGodOfAllThatWas Thanks for the detailed answer!

  • @ganeshmurugan157
    @ganeshmurugan157 3 роки тому +1

    Awesome video sir.can u uploaded video on icmp redirecting in mitm sir?

    • @Certbros
      @Certbros  3 роки тому

      Thanks for the suggestion. I've added it to the suggestion list. If I get more requests I will definitely look at making this.

  • @Gajendra463
    @Gajendra463 Рік тому

    I literally took CEH v11 Course but this small video gave me so much knowledge that I actually got from that class.

  • @saifalmarwani
    @saifalmarwani 2 роки тому

    many thanks Mate : _

  • @electroplank587
    @electroplank587 2 роки тому +1

    the style and flow of your videos are great. Looking forward to seeing more like these and CCNA material is really helping.

    • @Certbros
      @Certbros  2 роки тому

      Great to hear! Lots more to come.

  • @mackynikat8833
    @mackynikat8833 3 роки тому

    . this is nothing but great video though , keep uploading videos like these so that you will not only help to educate but i will also help to spread out the word to prevent cyber hacking

  • @charlenelouise4758
    @charlenelouise4758 3 роки тому

    i just hate configuring dhcp snooping in packet tracer, it doesn't work and it could be a lil buggy

  • @MA-nc8uc
    @MA-nc8uc 2 роки тому

    Thank you..Wonderfully done! Much appreciated

  • @slee2054
    @slee2054 2 роки тому

    awesome video! thank you for showing how it actually works! I studied Network+ but never knew how it worked and always wondered.

  • @abhik67590
    @abhik67590 3 роки тому +1

    So is it possible that i connect to unknown/free wifi in a cafe , so now it is my default gateway?
    If yes then if i login to http site then the free wifi guy can see my credential using wireshark?

    • @M3nt4LC4t
      @M3nt4LC4t 3 роки тому

      I think they cannot, even though they can see your traffic accessing Facebook. Because Facebook is using https, our credentials are encrypted.

    • @abhik67590
      @abhik67590 3 роки тому

      @@M3nt4LC4t if site is http then is it possible?

    • @M3nt4LC4t
      @M3nt4LC4t 3 роки тому +1

      @@abhik67590 yes it is possible. because http traffic are not encrypted. you can see example as in the video.

    • @helamanavalos9806
      @helamanavalos9806 3 роки тому +1

      Ussually you would see two wifi networks , like amm, Starbucks and Starbucks_official, being the first one the real wifi and the second one the wifi that the attacker created so people connects to that and spy traffic with wireshark.

    • @abhik67590
      @abhik67590 3 роки тому +1

      @@helamanavalos9806 ✌Thanks

  • @hellou3874
    @hellou3874 2 роки тому

    thank

  • @pankajholariya8331
    @pankajholariya8331 2 роки тому

    nice

  • @harkaman4205
    @harkaman4205 2 роки тому

    Sup man, keep going. Ur vids are very interesting

  • @Alexei_Nikolaev
    @Alexei_Nikolaev 3 роки тому

    Nice lesson, thanks! The only little thing is missed. The kali Linux settings that forward hacked user's traffic back to router.

  • @abdodana2637
    @abdodana2637 2 роки тому

    you are correct about https but what if attacker do SSL strip bro ?!!

  • @8080VB
    @8080VB 3 роки тому +1

    K , could you show the same in yersinia ? deploy this rogue attack on yersinia plz

    • @Certbros
      @Certbros  3 роки тому +1

      Thanks for the suggestion! I'll definitely look to make some Yersinia videos in the future.

    • @8080VB
      @8080VB 3 роки тому +1

      @@Certbros cool i'll wait

  • @pati6239
    @pati6239 3 роки тому +1

    Please make a video about APIs

  • @SzwarcuKX5
    @SzwarcuKX5 3 роки тому +5

    Lovely content

  • @neealdon2-g6j
    @neealdon2-g6j Рік тому

    Its so sad that so many people are missing out on these awsome videos😥

  • @sadisalgama9956
    @sadisalgama9956 3 роки тому

    Good video clip perfectly explained..!!!

  • @leothalion3983
    @leothalion3983 3 роки тому +1

    This was awesome!!!!!!!

  • @sijorilsenglarians7907
    @sijorilsenglarians7907 2 роки тому

    😍😍😍

  • @jessil77
    @jessil77 3 роки тому +1

    Loved it xo

  • @grandfatherm5774
    @grandfatherm5774 2 роки тому

    Real goat video

  • @angelnavedo8086
    @angelnavedo8086 Рік тому

    Thank You !

  • @martinacapparelli2359
    @martinacapparelli2359 2 роки тому

    Sorry, I don't understand what you do at 7:40. How can I open a Cisco router? Can you help me? I really don't know how to do

  • @zakariasabbagh
    @zakariasabbagh 2 роки тому

    Great video!!

  • @xxxtentacionforever3037
    @xxxtentacionforever3037 3 роки тому

    very nice

  • @abhik67590
    @abhik67590 3 роки тому +2

    Great video, already waiting for the next video.

    • @Certbros
      @Certbros  3 роки тому

      Thank you Abhishek!

  • @techstuff42
    @techstuff42 2 роки тому

    A tip... I went to increase the speed of the video only to realize it was at 2.0x already. So the tip, don't talk so very slow

  • @alfonzo7822
    @alfonzo7822 Рік тому

    Is it possible that planting malware on a device could then force all traffic to http so it can be intercepted? I'm dealing with a network attack and I've come to the conclusion that mitm is what I'm dealing with. Unfortunately the devices contain some kind of code that reconnects to some kind of server out there when I've rebooted the router. I think everything will need a clean install once I've figured out how to fix the mess I'm in . Got a new router but due to devices not being clean it's started all over again. Antivirus has found and cleaned heuristic Trojans but I can't figure out how to fix the TV 🫤