[11425] 2017-06-06_MOTS攻击技术分析

文档创建者:s7ckTeam
浏览次数:3
最后更新:2025-01-18
2017-06-06_MOTS攻击技术分析 M O T S f e i n i a o   F r e e B u f   2 0 1 7 - 0 6 - 0 6 * f e i n i a o F r e e B u f : 怀 : D N S M O T S M O T S   1 2 3 4 1
2 3 T C P   U D P 3 . 1   T C P T C P / I P T C P T C P T C P T C P f r e e b u f 6 7 ( S Y N ) 2 8 5 9 5 9 0 5 8 3 1 4 8 ( A C K + S Y N ) s e q + + 1 2 8 5 9 5 9 0 5 8 3 0 2 8 5 9 5 9 0 5 8 4 T C P .   3 . 1 . 1   D O S T C P D O S D O S R e s e t 1 2 Ø     D O S
M O T S D O S S Y N R e s e t + A C K D O S S Y N D O S R e s e t + A C K S Y N + A C K S Y N + A C K 1 I P 2 I P 3 I P T C P g o o g l e I P I P T C P T C P U D P 4 I P I P I P I P A C K = S Y N + 1 I P T C P Ø     D O S : R e s e t + a c k r e s e t
3 . 1 . 2   T C P M O T S T C P M O T S T C P T C P H T T P H T T P 广 H T T P H T T P D N S H T T P H T T P 1 2 访 w w w . f r e e b u f . c o m 广 3 1 I P I P 2 I P I P I P I P A C K =
S Y N + + 1 I P T C P 3 H T T P f r e e b u f < > 3 . 1 . 3   M O T S M O T S Ø     M O T S M O T S M O T S D O S H T T P Ø     I P T T L I D T T L H T T P H T T P T T L H T T P T T L H T T P H T T P T T L T T L T C P T T L T T L T C P   T T L 1 T T L T T L 2 T T L T T L T T L 使 t s h a r k T T L H T T P t s h a r k - i   e t h 0   - n     - Y   " ( t c p . f l a g s . s y n = = 1   a n d   t c p . f l a g s . a c k = = 1 )   o r ( h t t p . r e s p o n s e ) "     - T   f i e l d s   - e " i p . s r c "   - e   " t c p . s r c p o r t "   - e   " i p . d s t "   - e " t c p . d s t p o r t "   - e " i p . t t l " I P   I D I P   I D 使 I P   I D I P   I D 使 T s h a r k I P I D T s h a r k t s h a r k   - i   2   - Y   " t c p . s t r e a m   = =   0 "     - T   f i e l d s   - e " i p . s r c "   - e   " t c p . s r c p o r t "   - e   " i p . d s t "   - e   " t c p . d s t p o r t " - e   " i p . i d "
T C P M O T S 1 使 H t t p s V P N 2 T C P / I P T T L I D T T L I D T T L I D 3 3 . 2   U D P T C P U D P T C P U D P T C P 3 . 2 . 1   D O S U D P U D P D O S D O S 访 U D P D O S I C M P   P o r t   u n r e a c h a b l e I C M P   p o r t   u n r e a c h a b l e g o o g l e
1 I P I P 2 I P I P I P I P I C M P   p o r t u n r e a c h a b l e I P U D P U D P 3 I C M P   p o r t u n r e a c h a b l e 3 . 2 . 2   D N S G F W D N S D N S D N S D N S D N S D N S w w w . f r e e b u f . c o m   I P 1 2 0 . 5 5 . 2 2 6 . 2 0 7 D N S D N S D N S 1 . 2 . 3 . 4 D N S D N S w w w . f r e e b u f . c o m D N S 1 2 0 . 5 5 . 2 2 6 . 2 0 7 D N S D N S I P 1 . 2 . 3 . 4 D N S D N S D N S D N S f r e e b u f D N S
  1 D N S w w w . f r e e b u . c o m I P 2 D N S 3 D N S A 1 . 2 . 3 . 4 4 D N S A 1 2 0 . 5 5 . 2 2 6 . 2 0 7 5 1 U D P D N S 使 U D P D N S D N S D N S T r a n s a c t i o n   I D I D I D I D D N S D N S T r a n s a c t i o n   I D D N S T r a n s a c t i o n   I D 2 D N S I P D N S I P I P I P , I P U D P U D P 3 . 2 . 3  
D N S U D P M O T S                 1   2 I P D N S 使 广 1 D N S D N S D N S D N S D N S h t t p s : / / w w w . o p e n d n s . c o m / a b o u t / i n n o v a t i o n s / d n s c r y p t / 2 D N S I P   I D T T L 3 D N S 3 . 3           M O T S M O T S M O T S 线 M O T S : M O T S W A F 1 2 * f e i n i a o F r e e B u f

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则