3 ms·
Eli5 this attack pla
by coolThingsFirst 3y ago
Eli5 this attack pla
- jcul 3y agoI've no idea what nettby is. But ARP is how computers figure out what IP address is associated with a hardware / ethernet address, so they know what ethernet address to use for sending packets to a specific IP. ARP poisoning means you flood the network with fake ARP packets saying your ethernet address has the gateway IP or whatever IP. So then the other devices will forward packets to your machine instead of the intended destination. As nettby didn't use HTTPS it would then be trivial to capture / read the packets and figure out everyones' passwords. I.e. the messages would be plain text, unencrypted. Not exactly Eli5, but hope it helps.
- mtlmtlmtlmtl 3y agoThis is pretty much the reply I'd write, so I'll just add my endorsement. Couple more tidbits of information: Nettby was a Norwegian Myspace clone and it was all the rage back when I was in middle school(around 2007-2009 or thereabouts). ARP stands for Address Resolution Protocol. ARP has no security built in by default. This combined with the plaintext passwords made the attack trivial.
- coolThingsFirst 3y agoYes but isnt this possible only on LANs?
- mtlmtlmtlmtl 3y agoCorrect. I did this at school. It was early days of students being allowed laptops in class. We weren't actually allowed internet, but the school had an extremely basic wifi network that was WEP encrypted... So naturally I broke out Aircrack-ng and ameliorated that situation. And suddenly everyone was procrastinating on nettby in class.
- cqqxo4zV46cp 3y agoIt should also be said that HTTPS was seldom used outside of especially sensitive applications until ~2010 when someone packaged a HTTP MITM attack up into a handy Firefox extension. I think that Facebook used HTTPS for the actual login credential exchange, snd then bounced back to HTTP, which meant that the session cookie/s were still MITMable. It’s insane how long it took to see widespread HTTPS adoption.
- roughly 3y agoYes! Firesheep was the extension, and I think the combination of that and LetsEncrypt (which was in part a reaction to Firesheep) were the reason the web went from almost entirely decrypted by default to almost entirely encrypted by default in a matter of months. The capabilities had been there for years, but Firesheep made session hijacking a literal one-click affair and vividly highlighted the danger of unencrypted web traffic - it’s maybe the most impactful bit of white-hat hackery of all time.
- nijave 3y agoIirc Google said they'd start penalizing non https sites in search results and browser makers added much more aggressive warnings to http pages. It caused quite a commotion among small site operators.
- nicolas_t 3y agoI remember back in that time that a lot of apps had convoluted code to do this https only at login dance. All in the name of performance (because https was slower despite it being a premature optimization really). Switching to https only actually mostly helped simplify codebases...
- singingfish 3y agoyeah, a colleague and I ripped out all of the http / https dance out of a 20 year old code base a little while back. It simplified things a lot.