A compromised router is reconfigured by an attacker to redirect SMTP email traffic to the attacker's server before sending packets on to their intended destinations. Which IP header value would help expose anomalies in the path outbound SMTP/Port 25 traffic takes compared to outbound packets sent to other ports?
In a case study of a redirect tunnel set up on a router, some anomalies were noticed while watching network traffic with the TCPdump packet sniffer.
Packets going to port 25 (Simple Mail Transfer Protocol [SMTP] used by mail servers and other Mail Transfer Agents [MTAs] to send and receive e-mail) were apparently taking a different network path. The TLs were consistently three less than other destination ports, indicating another three network hops were taken.
Other IP header values listed, such as fragment offset. The acknowledgement number is a TCP, not IP, header field.
Verona
9 months agoJuliana
9 months agoHyun
9 months agoSvetlana
9 months agoCelestina
9 months agoDorthy
9 months agoCassi
10 months agoJennifer
10 months agoMarget
10 months agoMadonna
10 months agoAshton
10 months agoTerrilyn
10 months agoTalia
10 months agoKiera
10 months agoLelia
10 months ago