EMZETT.
Login

Spoofing

In short: Faking a false identity on a network — e.g. a forged sender address, to gain false trust or bypass security mechanisms.

In more detail: Common variants are IP spoofing (forged sender IP address in packets), ARP spoofing/poisoning (false mapping of IP to MAC addresses on the local network, to redirect traffic) and email spoofing (forged sender address for phishing). Spoofing is often the first step for further attacks such as man-in-the-middle.

In Depth

With ARP spoofing, one of the practically most effective variants on local networks, the attacker sends forged ARP replies to get other devices to falsely change their mapping of IP address to MAC address to point to the attacker’s machine:

Normal:        192.168.1.1 (router) -> belongs to MAC aa:aa:aa:aa:aa:aa
After
spoofing:      192.168.1.1 (router) -> victim falsely believes: MAC bb:bb:bb:bb:bb:bb (attacker)

All of ARP’s network trust rests on every device believing other devices’ replies without checking them — ARP itself has no authentication built in at all by design. This lets the attacker place themselves as a “man in the middle” between two communication partners (e.g. victim and router) and read all the traffic (sniffing) or even manipulate it, before forwarding it unchanged to stay undetected.

Email spoofing works differently: the SMTP protocol doesn’t by default check whether the stated sender is really correct — an attacker can put practically any address in the “From” field. Modern email systems, by contrast, use protection mechanisms such as SPF, DKIM and DMARC, which use a DNS record to define which servers are allowed to send emails on behalf of a domain — receiving mail servers can thereby increasingly reliably detect and filter out forged senders.

Other spoofing variants

Besides ARP and email spoofing, there are numerous other variants of the same basic principle: DNS spoofing (also DNS cache poisoning) manipulates DNS resolution so that a domain name falsely points to an attacker’s IP address instead of the real server — victims end up unnoticed on a fake copy of a website, even though they entered the correct address. Caller ID spoofing forges the displayed caller number in phone calls, often used for scam calls pretending to be a bank or authority. GPS spoofing sends forged satellite signals to manipulate the position calculated by a device — relevant, among other things, for drone defence or to fool location-based app features.

Protective measures against ARP spoofing

Because ARP itself has no concept of authentication, protection has to be applied at other levels: managed switches often support “dynamic ARP inspection”, where the switch itself checks ARP replies against a known, trusted list (e.g. from DHCP mappings) and drops suspicious packets before they reach the network. On the client side, static ARP entries for particularly critical devices (e.g. the router) can reduce the risk, but are hardly practical to maintain in large, dynamic networks. Encrypted connections (TLS/HTTPS) also reduce the damage even when an attacker successfully becomes a man-in-the-middle via ARP spoofing — they then see the traffic, but can’t read it in plain text without the matching key.

IP spoofing in DDoS attacks

IP spoofing also plays a central role in certain DDoS attack techniques: in a “reflection attack”, the attacker sends requests to harmless, publicly reachable servers (e.g. DNS or NTP servers) with a forged sender IP — the forged address of the actual victim. The responding server then sends its (often considerably larger) reply not to the attacker, but to the supposed sender, the actual victim, who is thereby flooded with a wave of unsolicited replies. This technique (“DNS amplification”, “NTP amplification”) makes IP spoofing an effective amplifier, because the attacker themselves only needs to invest a little bandwidth to generate a multiple of that amount as reply traffic at the victim.

See also: ARP, Malware