We have to talk about some security courses recently. We need to build a test platform for attacks and find the IDS of Blade. informer. the simulation test software v4.0 found that there was a problem with the compatibility after being installed on server 2008 r2 sp1, so we had to install it on Windows server 2003 under Hyper-V. We know that any attack test may bring security risks, and Hyper-V's Virtual Network Manager can create a network adapter that is only used inside the virtual machine itself, isolate the virtual machine from the real network environment. I can use this function. IDS. Informer can communicate between two NICs of a single host. What if two internal virtual NICs of Hyper-v are used?
Here is my test:
1. Prepare a virtual NIC-Virtual Network Manager-dedicated-name Test
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T03112D-0.png "" 634 "height =" 390 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T03124V-1.png "" 457 "height =" 317 "/>
2. Set SERVER2003
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T0311320-2.png "" 665 "height =" 381 "/>
Add two NICs
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T0314O0-3.png "" 660 "height =" 472 "/>
3. Set IDS. Informer-Sett-source machine-source NIC-IP-MAC
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T0311T6-4.png "" 658 "height =" 444 "/>
Destination virtual NIC-IP-MAC
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T0314U6-5.png "" 657 "height =" 384 "/>
4. Attack test-Attacks-select a dll-Attack to view the green traffic.
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T031O23-6.png "" 667 "height =" 468 "/>
Here, IDS. Informer uses the. dll file to simulate more than 600 attacks.
Here I simulate the AckCmd attack. The packet capture result is as follows:
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T0314053-7.png "" 682 "height =" 157 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T0313023-8.png "" 683 "height =" 159 "/>
650) this. width = 650; "style =" background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; border-top: 0px; border-right: 0px; padding-top: 0px "title =" image "border =" 0 "alt =" image "src =" http://www.bkjia.com/uploads/allimg/131227/0T031O44-9.png "" 690 "height =" 67 "/>
Erection completed. Let's test more attacks.