"Practical examples in the cybersecurity laboratory - UPEC"
DOI:
https://doi.org/10.32645/13906925.1002Keywords:
Cyber attack, Session Hijack, John the Ripper, CyberSeguridad-UPEC laboratoryAbstract
Currently through the internet there are people who seek to violate systems or applications, for this they use different cyberattacks, several techniques such as Session Hijack, or spoofing attack and tools such as John the Ripper, these are the most used attacks hackers to obtain the session of users connected to the network. This type of attack is carried out through the network, taking advantage of the weaknesses of the system or application, since it is known that sensitive information is transported between sessions, for this purpose, ARP poisoning is used with the Sniffer that allows to capture and visualize all the network traffic, thus obtaining the port and protocol that are being used for the connection. In this document, the practices were carried out in the UPEC Cybersecurity laboratory, this laboratory was implemented as part of the research project “Security and computer service in the Provincial Government of Carchi (Ecuador) and the Municipal Mayors of Pasto, Ipiales and Túquerres (Colombia) ”The practices showed the interception of a session to a user who is connected to the Centos virtual machine using Telnet, which is a protocol that allows access to another machine and to use it remotely from the Windows 7 virtual machine. Kali Linux was used as the attacker and carried out a network scan and applied "poisoning" to then access the connection, thus testing the ease with which session subtraction can be done to users who are connected, so it is He recommended using encryption protocols for the headers so that it is not so easy to access the victim's connection.

Downloads
Published
Issue
Section
License
Copyright (c) 2020 MARCO ANTONIO YANDÚN VELASTEGUÍ, JAIRO VLADIMIR HIDALGO GUIJARRO

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
El autor mantiene los derechos morales e intelectuales de su obra, autorizando a la editorial de la revista Sathiri la difusión y divulgación de su contenido con fines estrictamente académicos y de investigación, sin fines de lucro. Así mismo, se autoriza que la obra sea descargada y compartida con otras personas, siempre y cuando no sea alterada y se reconozca su autoria.