Skip to content

Latest commit

 

History

22 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Investigation-of-a-Session-Hijacking-via-MAC-Spoofing

CyberLab-04

Overview

This repository documents the analysis of a TCP session hijacking attack against a Telnet session.

The packet capture demonstrates an attacker taking over an active TCP connection by injecting packets after a change in the source MAC address.

image

Objectives

  • Examine the packet capture using Wireshark.
  • Identify the point where the source MAC address changes.
  • Identify suspicious network behavior.

Environment

  • Wireshark 4.x
  • Protocol: Telnet (TCP/23)
  • Capture Format: PCAP

Learning Objectives

  • Evaluate evidence of TCP session hijacking.
  • Identify packet injection
  • Detect Layer 2 spoofing

Releases

Packages

Contributors