Network and Protocol Attacks
You will learn how an attacker becomes the first hop, poisons a name, rides a session already open, or takes the path away. Interviewers use these to test whether you know the protocol underneath.
on this pageshowhide
explore
- Claimed Names and Addresses20 questions
- First-Hop Takeover4 questions
- Broadcast Name Fallbacks4 questions
- Racing the Resolver4 questions
- One-Way Source Spoofing4 questions
- The Endpoint Nobody Owns4 questions
- Riding an Established Session12 questions
- Authentication Already Spent4 questions
- Replay and Freshness4 questions
- Inside the Receive Window4 questions
- Paying for Unproven Requests12 questions
- What Runs Out First4 questions
- Amplification Factor4 questions
- Flood Capacity Supply4 questions
questions
page 2 of 2A service you run answered forged requests in a stranger's flood; why won't patching it help?
basics
~20 sNothing is broken. The service received well-formed requests and answered the address it was handed, exactly as specified, so the next release behaves identically. Only narrowing who may ask, or proving the asker's address, helps.
A blind attacker wants a long-lived TCP session down - is a forged reset or forged data the cheaper route?
basics
~20 sIt depends on the stack. Against an unhardened receiver the reset is far cheaper: any in-window value, no plausible acknowledgement, no application meaning, and one hit ends everything. Against an RFC 5961 receiver a reset needs an exact sequence match, so in-window data becomes the easier landing.
Which tenant operations must demand fresh proof of authentication, and what does that gate still not deny?
basics
~20 sThe ones that turn borrowed access into owned access: changing the password, enrolling a factor, editing a recovery address, granting delegated administration. The gate caps how durable the access becomes, and denies nothing the identity can already read or send.
A payment partner demands a 24-hour freshness window so its late retries are never rejected — what do you agree to?
basics
~20 sAgree only if remembered-identifier retention is extended to cover the whole window, because a window without matching memory is pure exposure. Price the extra storage, write the retention bound into the interface agreement, and keep partner test keys unacceptable in production.
Your staging DHCP server sits on the office VLAN: how does a client tell its lease from a rogue's?
basics
~20 sIt cannot. A client validates no server identity and takes the first acceptable answer, so a misplaced staging server and a hostile one are identical on the wire. Rogue is a claim about ownership, not about the packets.
Why is winning the WPAD name lookup worth more than winning a mistyped file-share name?
basics
~10 sA typo wins one connection from one host by accident. WPAD is asked for automatically by many hosts, and its answer is a configuration URL deciding where web traffic goes.
A publicity-driven crew promises an outage during your launch week - what does that predict?
basics
~20 sAn adversary class predicts shape and duration, not capability. A publicity-driven crew needs a visible outage an outsider can verify inside a named window, so expect cheap held slots against a browser-loadable surface, and a stopping rule tied to attention.
As a hosting provider, how do you justify funding source-address validation that protects other networks?
basics
~10 sStop arguing it on altruism and name what you capture: your address space's reputation, recurring abuse-handling cost, peer and contract pressure, and the customer-to-customer forgery the same validation stops inside your own estate.
Your registrar account for every company domain sits with marketing — what do you require, and how do you win it?
basics
~10 sTreat the registrar account as a root of trust: registry-level change locks on load-bearing domains, phishing-resistant sign-in, a company-controlled recovery address, two-person approval. Win it by buying marketing a fast approval path.
Your DNS zone sits with one team and cloud resources with dozens — who is accountable for names that outlive their targets?
basics
~20 sAccountability belongs with whoever creates the record, enforced by making the record part of the resource's lifecycle. A central zone team can gate and expire records but cannot know when a resource dies, so pure centralisation fails.
The board asks whether a 600 Gbps flood means a well-resourced adversary. How do you answer?
basics
~20 sPeak volume no longer indicates resources. Very large short bursts are rented cheaply from fleets somebody else built and holds, so the headline number describes the seller's stock. Duration and adaptation are what imply a budget.
Your customers' devices are amplifying a stranger's flood; how do you decide whether to close the service?
basics
~10 sDecide it as a cost case you cannot justify on your own harm, because you have none. Weigh donated transit and peer or contract exposure against support cost, then change the provisioning default first.
Your peers won't all deploy TCP-AO on 300 BGP sessions - how do you allocate blind-injection defence?
basics
~20 sSpend unilateral hardening everywhere first because no peer has to agree to it, buy hop-count checking on every peer who will accept a change window, and reserve keyed per-segment authentication for the sessions whose loss actually hurts and where you control both ends.
How long may a renewing session go without a fresh authentication ceremony when the business refuses prompts?
basics
~20 sSet a finite absolute lifetime and defend it: an unbounded one prices one acquired session at everything that identity reaches, forever. Spend your few prompts on operations that create durable access, and differentiate by population rather than by seniority.
showing 31–44 of 44