CHFI v3 Module 23 Router Forensics.pdf

(1160 KB) Pobierz
Computer Hacking
Forensic Investigator
Module XXIII
Router Forensics
Scenario
Two Pinehurst men, Dalton Johnson, 37, and David Alan Brady, 40, were arrested on
September 14, 2006 on the charges of selling prescription drugs over the Internet
14 2006,
Internet.
Their company allegedly sold generic versions of prescription steroids, drugs such
as Valium and Xanax, and sex-enhancing drugs such as Viagra and Cialis. They
were accused of selling unregulated d
d f lli
l d drugs manufactured i Belize and marketed
f
d in li
d
k d
through "spam" emails as low-price Canadian drugs. The emails would direct
customers to one of several websites where they could order the drugs which would
be hi
b shipped f
d from B li
Belize.
The Drug Enforcement Agency (DEA) and the Food and Drug Administration
(FDA) conducted the investigation along with other agencies. Moore County
sheriff's deputies along with federal investigators raided the homes of the two
Pinehurst men and arrested them.
Source: http://www.thepilot.com/stories/20060923/news/local/20060923two.html
EC-Council
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
Module Objective
This module will familiarize you with the following:
Routers
Router Architecture
Routing Information Protocol
Types of Router Attacks
Routing T bl P i
R ti Table Poisoning
i
Router Forensics vs. Traditional Forensics
Investigating Routers
Router Logs
Incident Forensics
Router Auditing Tools
EC-Council
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
Module Flow
An Introduction
to Routers
Routing Information
Protocol
Types of Router Attacks
Investigating Routers
Router Forensics vs.
Traditional Forensics
Routing Table Poisoning
Router l
R t logs
Incident Forensics
I id
F
i
Router A diti Tools
R t Auditing T l
EC-Council
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
What is a Router?
A router is a computer networking device that forwards
data packets across a network
p
It is connected to at least two networks, commonly a LAN
and its ISPs network or two LANs
Routing occurs at layer 3 (the Network layer e.g. IP) of the
eg
OSI seven-layer protocol stack
Router software determines which of the several possible
paths b t
th between th
those addresses suit a particular
dd
it
ti l
transmission
Uses headers and forwarding tables to determine the best
path f f
h for forwarding the packets
di
h
k
Uses protocols such as ICMP to communicate and
configure the best route between any two hosts
EC-Council
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
Zgłoś jeśli naruszono regulamin