Skip to content

Nouman-J-Nizami/Null-session-e-ARP-Poisoning-e-Extra

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

ARP Poisoning, MITM and SMB Null Session Security Analysis Lab

Overview

This repository documents a cybersecurity laboratory focused on network attack simulation, traffic interception, SMB enumeration, and vulnerability assessment within an isolated virtual environment.

The project combines practical offensive security techniques with defensive analysis to demonstrate how insecure protocols and misconfigured services can expose sensitive information and increase organizational risk.


Objectives

The main goals of this laboratory were:

  • Perform a Man-in-the-Middle (MITM) attack using ARP Poisoning
  • Analyze network traffic using Wireshark
  • Intercept unencrypted HTTP credentials
  • Investigate SMB Null Session vulnerabilities
  • Enumerate network resources without authentication
  • Access exposed resources through insecure Samba configurations
  • Study mitigation and detection techniques for network attacks

Laboratory Environment

Attacker Machine

  • Kali Linux

Victim Machine

  • Windows 10

Vulnerable Target

  • Metasploitable

Network Infrastructure

  • Private Virtual Network
  • Virtual Gateway

Tools Used

  • Ettercap
  • Wireshark
  • SMBClient
  • Enum4Linux
  • Kali Linux
  • Metasploitable
  • Windows 10

Project 1 – ARP Poisoning and MITM Attack

Description

A Man-in-the-Middle attack was simulated using ARP Spoofing techniques to redirect victim traffic through the attacker's machine.

The objective was to observe how ARP cache manipulation can be used to intercept unencrypted communications within a local network.

Activities Performed

  • Network discovery
  • Host identification
  • ARP cache analysis
  • ARP Spoofing execution
  • MITM attack validation
  • HTTP traffic interception
  • Credential capture
  • Packet inspection with Wireshark

Key Findings

  • Successful ARP cache poisoning
  • Traffic redirection through attacker machine
  • HTTP credentials exposed in clear text
  • Verification of intercepted credentials
  • Analysis of ARP packets and HTTP requests

Project 2 – SMB Null Session Enumeration

Description

The second phase focused on exploiting an SMB Null Session vulnerability in a Metasploitable environment.

Anonymous access was used to enumerate shared resources and investigate the security impact of insecure Samba configurations.

Activities Performed

  • SMB share enumeration
  • Anonymous access validation
  • Samba configuration analysis
  • POSIX mode testing
  • Symbolic link creation
  • Filesystem traversal
  • Sensitive file access verification
  • Enum4Linux reconnaissance

Key Findings

  • Anonymous SMB access allowed
  • Accessible shared resources
  • Enumeration of system information
  • Exposure of sensitive filesystem content
  • Additional information disclosure through SMB services

Security Risks Demonstrated

ARP Poisoning

Potential impacts:

  • Credential theft
  • Session hijacking
  • Traffic interception
  • Network surveillance
  • Data exposure

SMB Null Session

Potential impacts:

  • Information disclosure
  • User enumeration
  • Resource discovery
  • Attack surface expansion
  • Facilitation of further compromise

Defensive Measures

ARP Poisoning Mitigation

  • Dynamic ARP Inspection (DAI)
  • DHCP Snooping
  • Static ARP entries
  • Network segmentation
  • Secure protocols (HTTPS, SSH, VPN)
  • Continuous monitoring

SMB Security Hardening

  • Disable anonymous access
  • Disable SMBv1
  • Restrict exposed shares
  • Apply security patches
  • Implement Group Policy restrictions
  • Monitor SMB activity
  • Restrict ports 139 and 445

Skills Demonstrated

  • Network Traffic Analysis
  • Wireshark Investigation
  • ARP Protocol Analysis
  • MITM Attack Detection
  • Credential Exposure Assessment
  • SMB Enumeration
  • Vulnerability Assessment
  • Security Monitoring
  • Threat Analysis
  • Security Reporting

Learning Outcomes

This project provided practical experience in understanding how insecure network protocols and misconfigured services can be abused by attackers.

The laboratory reinforced the importance of secure configurations, encrypted communications, network segmentation, continuous monitoring, and proper vulnerability management.


Disclaimer

All activities described in this repository were performed exclusively in an isolated laboratory environment for educational, research, and authorized cybersecurity training purposes.


Author

Nouman Javed Nizami

Cybersecurity Analyst | Network Security & Threat Analysis Laboratory

About

Cybersecurity laboratory covering ARP Poisoning, Man-in-the-Middle attacks, credential sniffing, SMB Null Session exploitation, network traffic analysis, and security mitigation techniques using Ettercap, Wireshark, and Samba enumeration.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

No releases published

Packages

 
 
 

Contributors