A Framework For Reverse Tcp Backdoor Attack And Computer Forensic On Linux Os

Joshua O. Odumosu · Maryland Shared Open Access Repository (USMAI Consortium) · 2016

In this work, a framework for launching a reverse TCP attack and performing computer forensic examination on the image of the attacked host was implemented, this was conducted and tested on an isolated cybersecurity network testbed. It involves implementing a reverse TCP backdoor targeting a Linux Ubuntu operating system (OS) making use of Metasploit framework (penetration testing tool) payloads embedded within Kali Linux. Once the attack is successful, a malicious file was planted on the target host which gives a persistent logon access to the attacker machine using the backdoor. To investigate the attack event, Wireshark tool (a network sniffer) was used to analyze the communication between the two computers and computer forensic examination was carried out to analyze the image of the target host. The image file of the compromised machine was collected remotely over a network using another host serving as a collection host. Afterwards, several libraries and forensic tools were used to perform forensic analysis on the image.

Read the paper · More papers on PaperTik