ENCRYPTION AND AUTHENTICATION
- Layout topology for this exercise:
data:image/s3,"s3://crabby-images/7976b/7976ba92496bcb326d75fcfdd0080c0743180698" alt=""
- In this exercise encryption is used to avoid eavesdropping and IDS detection. Also, authentication ensures that only the desired partner is able to establish the connection.
- The command structure is similar to the usual bind shell with the only differences of using ncat for the command, --ssl for encryption, and --allow for authentication.
- Windows specifies that the only allowed host to communicate via ncat with him will be the Kali machine, and also that the connection will be encrypted:
data:image/s3,"s3://crabby-images/2848a/2848abc85fb3afa295515940aa5fdec39937655f" alt=""
- Kali launches the connection also with --ssl encryption:
data:image/s3,"s3://crabby-images/0dae1/0dae118a34bc1bfb8d95e14623688d8d84a48dc2" alt=""