π¨NTP Spoofing
Last updated
Last updated
Distributing accurate time is a vital part of sustaining network infrastructure. Itβs also a critical element of network security, both when it comes to the expiry dates on certificates and timestamped system logs used for troubleshooting.
NTP Spoofing is hard to detect and the only mitigation is NTP encryption or synchronizing network time with GPS, so this type of attack is not as obvious as ARP spoofing or other types of spoofing for that matter.
A scapy script for spoofing NTP responses with an MITM attack
ARP-Cache-Poisons the target and the gateway
Positions your machine between target and gateway in MITM attack
Listens for NTP-responses from gateway to target
Modifies the NTP-timestamps
example: