반응형
![dhcp starvation 토폴로지](https://blog.kakaocdn.net/dn/kMhZw/btrrPgJjfbA/fmmhSP5iRB99cUGBHkChLk/img.png)
![네이버 확인](https://blog.kakaocdn.net/dn/L182v/btrrQsPOipz/yCw2KjsXoyk3NVfAFyF5uK/img.png)
![dsw 장비 ospf 확인](https://blog.kakaocdn.net/dn/rdB5O/btrrP42GKhL/CHof00kkjeWz3ToBejVzj0/img.png)
GW와 DSW 사이의
Ethernet 0/0과 Vlan50구간은 point-to-point로 설정하였습니다.
![인터페이스 설정](https://blog.kakaocdn.net/dn/bNwcCS/btrrJuhIG9F/Kskt5N1MXQXXAG3PvcKv30/img.png)
![점 대 점으로 연결](https://blog.kakaocdn.net/dn/y1xNP/btrrP4PayfR/5cHq4N9e9BrTmgO9dckouk/img.png)
#show run
![show run 확인](https://blog.kakaocdn.net/dn/bpb8rX/btrrReRhBIs/tZvFW0FdNkIrclwDc12Tx0/img.png)
![포인트 투 포인트 설정 확인](https://blog.kakaocdn.net/dn/3BWvz/btrrJlSpgZD/4vxSkzvUuilvvySTYJRdMk/img.png)
OSPF는 neighbor를 맺은 후 routing을 교환하고, routing을 결정하기 위하여 process를 거치게 되는데
그중 하나인 hello interval을 수정을 하겠습니다.
hello interval은 hello packet을 몇 초에 한 번씩 날려주냐,라는 결정을 하기 위한 시간입니다.
DSW : interface vlan 50에사
GW : interface Ehternet 0/0
![인터벌 설정](https://blog.kakaocdn.net/dn/G4oP5/btrrOc1uiGa/GZR6PzBW5QNGnbNxYeIChk/img.png)
![게이트웨이도 인터벌 설정](https://blog.kakaocdn.net/dn/9Opp0/btrrPOy1Hd6/L2LvdoLKrtxLe8NXCiibck/img.png)
![해당 인터페이스 확인](https://blog.kakaocdn.net/dn/JvuBN/btrrQsbb6D7/e56ibGlwJd0q6ljgaFcB5k/img.png)
![인터페이스 ospf 설정확인](https://blog.kakaocdn.net/dn/LpHs6/btrrPoUVpfx/cQtjuF64xBFY9Kk7e56gg1/img.png)
윈도우 서버 2008 설정
![윈도우 서버 2008 설정](https://blog.kakaocdn.net/dn/efvNBH/btrrKJeoZYP/2hpRbkttmaQMi3z4AKVEv1/img.png)
![윈도우서버 2008 핑 확인하기](https://blog.kakaocdn.net/dn/cMxG0v/btrrLNHH6Kf/YNodBwgiQphpohe1KUZTWK/img.png)
![핑 잘가는거 확인 했으면 다음단계로](https://blog.kakaocdn.net/dn/ZCtcr/btrrLOmgW16/cB9e4zv0ThrE6Q2A9j8d91/img.png)
DHCP 서버 올리겠습니다.
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/dt2qYh/btrrLMoeLcb/tkzHzbYEbPHZIWF5jXTmj0/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/cyqnSj/btrrJHHJ0ez/BORfdoWs9wKO8KTl00edPk/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/n5hNl/btrrJTn8fW9/A3RaMcCC7ZSd1KTX9yzN3k/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/dr9Gg4/btrrPnVXYVA/6yRoIexywj2lKwDwOIr671/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/dlsqbm/btrrQsI061G/igRg4BVrVUcLNSe9jFGKR1/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/Q4zjI/btrrKHucCbo/i1PWUMceAb1AYnSYEt11Ck/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/4PHni/btrrPG8N9nO/kWdJWOKS1X8u7KTRkEOCBk/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/tK4rW/btrrQzg5u0g/BgnkrL1KPYastdPKidpXjk/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/bdzkQ2/btrrJUAvs82/PcPoKcHrEFB6av8kDcUmUK/img.png)
![dhcp 서버 설치](https://blog.kakaocdn.net/dn/6A4XO/btrrPPq9FSq/SUeGKG7dKaDFgk1mA1OcRK/img.png)
윈도우서버 구성 완료
![hdcp클라이언트 확인](https://blog.kakaocdn.net/dn/K9z0H/btrrPgJjfab/qKKGTDzQKjVYZdg7rHK7sK/img.png)
![라우터 dhcp 설정](https://blog.kakaocdn.net/dn/cxeggV/btrrOdzhqHY/PFotcW8K8jl9bPsfkkmU0k/img.png)
설정 후 Ping 확인
![핑 확인](https://blog.kakaocdn.net/dn/c6WciH/btrrJl51dYX/IRYjN4C3A2GkEfCIqWLncK/img.png)
![장비간의 핑 확인](https://blog.kakaocdn.net/dn/qQXcy/btrrQ7q5UmJ/CSKiakVx6MEnryo0jowkF0/img.png)
우분투 기존 static 방식에서 dhcp 방식으로 변경
nano or vi
/etc/network/interfaces
![우분투](https://blog.kakaocdn.net/dn/bKlZel/btrrReX47sf/CczNSPu3DvqH05QPZzGPe1/img.png)
![우분투 아이피 확인](https://blog.kakaocdn.net/dn/6nIS0/btrrKHAXUKQ/g87qDCf6okaXIgas2NkGUK/img.png)
Starvation Attack
![dhcp attack](https://blog.kakaocdn.net/dn/cKdKxX/btrrKwzciZ3/2kBIkaN5uy9Jv5tMxqxL90/img.png)
공격 이후 vlan 30 때의 dhcp 사용 개수가 0%로 변경이 된 것을 확인 가능합니다.
![공격 후 dhcp 서버 상태](https://blog.kakaocdn.net/dn/0Hpuz/btrrKIUgnXF/iY1258A0VPwwDbO8qCEE80/img.png)
반응형
'보안 > Network' 카테고리의 다른 글
port security & macof (1) | 2022.01.26 |
---|---|
DHCP Starvation attack & DHCP Spoofing attack (0) | 2022.01.26 |
DHCP Snooping & Source guard (0) | 2022.01.26 |
Arp Inspection (man-in-the-middle attack) (0) | 2022.01.26 |
VTP Server & Client (0) | 2022.01.26 |