YoVDO

Bypassing Advanced Device Profiling with DHCP Packet Manipulation

Offered By: NorthSec via YouTube

Tags

NorthSec Courses Cybersecurity Courses Network Security Courses Ethical Hacking Courses Risk Mitigation Courses

Course Description

Overview

Explore advanced device profiling bypass techniques through DHCP packet manipulation in this NorthSec conference talk. Delve into Network Access Control mechanisms, focusing on sophisticated device identification methods beyond simple MAC address checks. Learn how crafted DHCP packets can trick inspection engines into perceiving attacking devices as legitimate. Examine case studies demonstrating successful bypasses, understand associated risks, and discover mitigation strategies. Gain insights into a novel client-based DHCP attack that differs from traditional denial of service or rogue server approaches. Follow along as the speaker presents a proof-of-concept tool for defining custom DHCP payloads to mimic arbitrary device fingerprints, filling a gap in publicly available resources on this topic.

Syllabus

Introduction
Outline
What is Network Access Control
Where is it implemented
Two layers of defense
Device profiling
Device profiling mechanics
DHCP discover packet
Vendor class identifier
DHCP profiler policy
Bypass device profiling
Case study A
Case study B
Case study C
Risk mitigation
Proof of concept


Taught by

NorthSec

Related Courses

I Am Become Loadbalancer, Owner of Your Network
NorthSec via YouTube
The Risks of RDP and How to Mitigate Them
NorthSec via YouTube
Authentication Challenges in SaaS Integration and Cloud Transformation
NorthSec via YouTube
Building CANtact Pro - An Open Source CAN Bus Tool
NorthSec via YouTube
Unmasking the Chameleons of the Criminal Underground
NorthSec via YouTube