{"id":7307,"date":"2024-04-18T15:14:23","date_gmt":"2024-04-18T12:14:23","guid":{"rendered":"https:\/\/www.inetmar.com\/blog\/?p=7307"},"modified":"2024-07-29T10:03:59","modified_gmt":"2024-07-29T07:03:59","slug":"ortadaki-adam-mitm-saldirisi-nedir","status":"publish","type":"post","link":"https:\/\/www.inetmar.com\/blog\/ortadaki-adam-mitm-saldirisi-nedir\/","title":{"rendered":"Ortadaki Adam (MitM) Sald\u0131r\u0131s\u0131 Nedir?"},"content":{"rendered":"<p>Man in the middle T\u00fcrk\u00e7esi <strong>ortadaki adam sald\u0131r\u0131s\u0131<\/strong> \u015feklinde olup siber sald\u0131r\u0131lar aras\u0131nda yer al\u0131r. A\u011fda iki ba\u011flant\u0131 aras\u0131na girilmesi, iki ba\u011flant\u0131 aras\u0131ndaki ileti\u015fimin dinlenmesi ve de\u011fi\u015ftirilebilmesi bu sald\u0131r\u0131y\u0131 a\u00e7\u0131klayan durumlard\u0131r. Bu sald\u0131\u011f\u0131 t\u00fcr\u00fcnde a\u011fdaki paketler ele ge\u00e7irilerek manip\u00fcle edilebilir.<\/p>\n<p>A\u011f \u00fczerinden kullan\u0131lan en eski sald\u0131r\u0131 y\u00f6ntemleri aras\u0131nda yer alan MitM sald\u0131r\u0131s\u0131 ile ki\u015filerin mahremiyeti ortadan kalkar. Ortadaki ki\u015fi g\u00f6r\u00fc\u015fmeleri dinler ve isterse bunlar\u0131 de\u011fi\u015ftirerek ki\u015finin farkl\u0131 \u015fekilde y\u00f6nlendirilmesini sa\u011flar. Bu sald\u0131r\u0131 t\u00fcr\u00fc \u00f6zellikle a\u00e7\u0131k Wi-Fi a\u011flar\u0131n\u0131n kullan\u0131ld\u0131\u011f\u0131 yerlerde daha kolay olarak yap\u0131labilir.<\/p>\n<p>G\u00fcn\u00fcm\u00fczde de hala kullan\u0131lan bu sald\u0131r\u0131 t\u00fcr\u00fc ile ki\u015finin banka bilgileri, \u015fifreleri, e-postalar\u0131, ki\u015fisel verileri ele ge\u00e7irilebilir. Dolay\u0131s\u0131yla doland\u0131r\u0131lma ama\u00e7l\u0131 olarak yo\u011fun olarak kullan\u0131ld\u0131\u011f\u0131n\u0131 s\u00f6ylemek m\u00fcmk\u00fcnd\u00fcr.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-7311 aligncenter\" src=\"https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a1-300x188.png\" alt=\"\" width=\"701\" height=\"439\" srcset=\"https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a1-300x188.png 300w, https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a1-1024x640.png 1024w, https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a1-768x480.png 768w, https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a1.png 1064w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><br \/>\nVerimlilik i\u00e7in en uygun <a class=\"waffle-rich-text-link\" href=\"https:\/\/www.inetmar.com\/hosting\/windows-hosting\/\">Windows hosting<\/a> paketlerimizi inceleyin.<\/p>\n<h2><strong>MitM Nedir?<\/strong><\/h2>\n<p><strong>MitM nedir<\/strong> sorusu son y\u0131llarda ki\u015fisel veri g\u00fcvenli\u011fi ihtiyac\u0131n\u0131n \u00fcst seviyelere \u00e7\u0131kmas\u0131ndan dolay\u0131 sorulmaktad\u0131r. Teknoloji ile i\u00e7 i\u00e7e bir hayat\u0131n art\u0131k toplumun her kesiminde oldu\u011fu g\u00fcn\u00fcm\u00fczde ki\u015fisel verilerinizi korumak i\u00e7in MitM kavram\u0131n\u0131 bilmeniz \u00f6nem arz ediyor. Bu siber sald\u0131r\u0131 t\u00fcr\u00fcn\u00fcn mant\u0131\u011f\u0131 asl\u0131nda olduk\u00e7a basittir. Sald\u0131rgan kendi bilgisayar\u0131 \u00fczerinden kar\u015f\u0131s\u0131ndaki ki\u015finin cihaz\u0131nda gizli bir ba\u011flant\u0131 olu\u015fturur. Bu \u015fekilde ona gelen mesajlar\u0131 kontrol edebilir ve isterse de\u011fi\u015ftirebilir. MitM sald\u0131r\u0131s\u0131na u\u011frayan ki\u015fi ileti\u015fim kurdu\u011fu ki\u015finin farkl\u0131 biri oldu\u011funu anlayamaz.<\/p>\n<p>MITM sald\u0131r\u0131s\u0131nda ki\u015finin a\u011f\u0131na girerek onun cihaz\u0131na ba\u011flanan k\u00f6t\u00fc niyetli ki\u015fi di\u011fer ki\u015filerle g\u00f6r\u00fc\u015fmelerini dinler. Onlar\u0131n mesajlar\u0131n\u0131 kendi istedi\u011fi y\u00f6nde de\u011fi\u015ftirir. Son y\u0131llarda kablosuz a\u011f kullan\u0131m\u0131nda art\u0131\u015f oldu\u011funu g\u00f6rmek m\u00fcmk\u00fcnd\u00fcr. Bu durum da en eski siber sald\u0131r\u0131 y\u00f6ntemi olan MitM i\u00e7in ki\u015fileri savunmas\u0131z b\u0131rakmaktad\u0131r. Bu sald\u0131r\u0131 y\u00f6ntemi ile \u015firketlerin bilgisayarlar\u0131na ba\u011flanma ve m\u00fc\u015fterilerin ki\u015fisel verilerinin \u00e7al\u0131nmas\u0131 da s\u00f6z konusu olmaktad\u0131r.<\/p>\n<h2><strong>MitM Neden Tehlikelidir?<\/strong><\/h2>\n<p>Sald\u0131rgan taraf\u0131ndan olu\u015fturulan bir ara sunucuya ba\u011flanan ki\u015fi bundan habersiz olarak a\u011f \u00fcst\u00fcnden g\u00f6r\u00fc\u015fmeler ger\u00e7ekle\u015ftirir. Bu s\u0131rada sald\u0131rgan, ki\u015finin bilgisayar\u0131na, telefonuna ula\u015f\u0131r ve onun mesajlar\u0131na ve cihaz\u0131nda olan di\u011fer bilgilere eri\u015febilir. <strong>MitM neden tehlikelidir<\/strong> konusunu incelerken \u00f6ncelikle g\u00fcn\u00fcm\u00fczde bilgisayarlar\u0131n ve telefonlar\u0131n adeta insanlar\u0131n veri bankalar\u0131 oldu\u011fu g\u00f6z \u00f6n\u00fcne al\u0131nmal\u0131d\u0131r. Yani ki\u015fisel veriler, ikinci taraflar ile yap\u0131lan g\u00f6r\u00fc\u015fmeler bu cihazlarda yer al\u0131r. Uzaktan cihaza yap\u0131lan sald\u0131r\u0131lar ile bu bilgiler elde edilir. Hatta ki\u015finin \u015fifreleri de\u011fi\u015ftirilerek kendi hesaplar\u0131na eri\u015fimleri de engellenebilir.<\/p>\n<p>MitM siber sald\u0131r\u0131 y\u00f6ntemidir ve k\u00f6t\u00fc niyetli olarak kullan\u0131l\u0131r. Casusluk ve doland\u0131rma bu y\u00f6ntemin kullan\u0131lma nedenleri aras\u0131nda ba\u015fta yer al\u0131r. K\u00f6t\u00fc niyetli olan sald\u0131rgan ki\u015finin banka bilgilerini alarak onun hesab\u0131ndaki paray\u0131 kendine aktarabilir. Kredi kart\u0131 ile al\u0131\u015fveri\u015f yapar ve \u00f6zellikle kripto para c\u00fczdan\u0131 olmas\u0131 halinde bunu da ele ge\u00e7irir.<\/p>\n<p>MitM bireysel cihazlara eri\u015fimde oldu\u011fu gibi \u015firketlerin cihazlar\u0131na eri\u015fim i\u00e7in de kullan\u0131lan sald\u0131r\u0131 y\u00f6ntemleri aras\u0131nda yer al\u0131r. \u015eirketin m\u00fc\u015fterilerinin bilgilerini ele ge\u00e7irebilir ve \u015firketin i\u015flerinin bozulmas\u0131na neden olabilir. Toplumda kaos yaratma ve d\u00fczeni bozma amac\u0131yla da bu y\u00f6ntem kullan\u0131labilir. Kullan\u0131lan cihaz\u0131n ekran g\u00f6r\u00fcnt\u00fcleri al\u0131nabilir ve bu g\u00f6r\u00fcnt\u00fcler yine k\u00f6t\u00fc niyetli olarak kullan\u0131labilir.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-7320 aligncenter\" src=\"https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a33-300x228.png\" alt=\"\" width=\"521\" height=\"396\" srcset=\"https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a33-300x228.png 300w, https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a33.png 573w\" sizes=\"auto, (max-width: 521px) 100vw, 521px\" \/><\/p>\n<h2><strong>MitM Sald\u0131r\u0131 Y\u00f6ntemleri<\/strong><\/h2>\n<p><strong>MitM sald\u0131r\u0131 y\u00f6ntemleri<\/strong> sald\u0131rgan\u0131n niyetine ba\u011fl\u0131 olarak ortaya \u00e7\u0131kar. Sald\u0131rgan, ki\u015finin bilgisayar ya da telefonuna eri\u015fim sa\u011flar ve onu yanl\u0131\u015f hedeflere y\u00f6nlendirir. Sahte web sitelerine y\u00f6nlendirme, \u00e7erezlerini \u00e7alma, bilgilerini de\u011fi\u015ftirme i\u00e7in kullan\u0131lan y\u00f6ntemler aras\u0131nda \u015funlar bulunur:<\/p>\n<ul>\n<li><strong>Replay (Yeniden oynatma) sald\u0131r\u0131s\u0131:<\/strong> Uzaktan cihaz\u0131n\u0131za eri\u015fen sald\u0131rgan bilgilerinize sahip olur ve daha \u00f6nce yapt\u0131\u011f\u0131n\u0131z i\u015flemleri tekrar eder. Bu y\u00f6ntem doland\u0131rma ama\u00e7l\u0131 olarak \u00e7ok fazla tercih edilir.<\/li>\n<li><strong>E-mail hijacking:<\/strong> Bu y\u00f6ntemde sald\u0131rganlar bankalar\u0131n eposta adreslerini taklit ederler. Kurbana g\u00f6nderilen epostalar ile onun \u015fifreleri ele ge\u00e7irilir. Sald\u0131rgan bankaya da sahte epostalar g\u00f6nderebilir ya da onun eposta sistemine girerek m\u00fc\u015fterileri ile olan g\u00f6r\u00fc\u015fmelerini ele ge\u00e7irerek bunu doland\u0131rma ama\u00e7l\u0131 olarak kullanabilir.<\/li>\n<li><strong>DNS sahtekarl\u0131\u011f\u0131:<\/strong> Sald\u0131rgan, sunucuya eri\u015ferek bir web sitesinin kay\u0131tlar\u0131n\u0131 kendi web sitesinin bilgileri ile de\u011fi\u015ftirir. Bu \u015fekilde kurban sahte bir web sitesini fark\u0131nda olmadan ziyaret eder. MitM sald\u0131r\u0131lar\u0131nda bu y\u00f6ntem ki\u015fisel verilerin \u00e7al\u0131nmas\u0131 ve doland\u0131rma ama\u00e7l\u0131 olarak \u00e7ok fazla kullan\u0131l\u0131r.<\/li>\n<li><strong>Wi-Fi dinleme:<\/strong> A\u00e7\u0131k bir Wi-Fi a\u011f\u0131na giren sald\u0131rgan kendi a\u011f\u0131n\u0131 kurar. Bu \u015fekilde kullan\u0131c\u0131lar onun a\u011f\u0131 \u00fczerinden ileti\u015fim kurar. Sald\u0131rgan da kendi a\u011f\u0131 \u00fczerinden yap\u0131lan b\u00fct\u00fcn ileti\u015fimi ele ge\u00e7irebilir ve istedi\u011fi bilgilere eri\u015febilir.<\/li>\n<li><strong>ARP spoofing:<\/strong> Bu sald\u0131r\u0131da ARP paketleri \u00e7\u00f6z\u00fcmlenir ve s\u00fcrekli olarak ki\u015finin cihaz\u0131na mesaj g\u00f6ndermeye zorlan\u0131r. Kullan\u0131c\u0131n\u0131n bir istek g\u00f6ndermesi halinde sald\u0131rgan\u0131n bilgisayar\u0131na ba\u011flan\u0131l\u0131r ve bilgileri ele ge\u00e7irilir.<\/li>\n<li><strong>SSL hijacking:<\/strong> SSL taray\u0131c\u0131 ile web sunucusu aras\u0131nda g\u00fcvenli\u011fi sa\u011flamak amac\u0131yla olu\u015fturulan bir sistemdir. Siber sald\u0131rgan SSL s\u0131y\u0131rma olarak da bilinen y\u00f6ntemle bu \u00f6zelli\u011fin olmad\u0131\u011f\u0131 s\u00fcr\u00fcm\u00fcn\u00fc kullan\u0131c\u0131ya g\u00f6ndererek onunla bu \u015fekilde ileti\u015fime ge\u00e7er.<\/li>\n<li><strong>Taray\u0131c\u0131 \u00e7erezlerinin \u00e7al\u0131nmas\u0131:<\/strong> Pek \u00e7ok web sitesi daha \u00f6nce yapt\u0131\u011f\u0131n\u0131z ziyaretleri ve ziyaretlerde yapt\u0131\u011f\u0131n\u0131z i\u015flemleri \u00e7erez olarak kaydeder. Sald\u0131rgan bu kaydedilmi\u015f bilgileri ele ge\u00e7irerek k\u00f6t\u00fc niyetli olarak kullan\u0131r.<\/li>\n<li><strong>Man-in-the-Browser:<\/strong> Bu y\u00f6ntemde kullan\u0131c\u0131 ger\u00e7ek bir siteyi ziyaret eder ama sitede g\u00f6rd\u00fckleri sald\u0131rgan taraf\u0131ndan kontrol edilir. Girdi\u011finiz sitede yapt\u0131\u011f\u0131n\u0131z b\u00fct\u00fcn i\u015flemler g\u00f6r\u00fclebilir ve kaydedilir. Bu \u015fekilde banka bilgileriniz \u00e7al\u0131narak doland\u0131rma ama\u00e7l\u0131 kullan\u0131l\u0131r.<\/li>\n<\/ul>\n<h2><strong><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-7315\" src=\"https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a2-300x197.png\" alt=\"Ortadaki Adam Sald\u0131r\u0131s\u0131\" width=\"586\" height=\"385\" srcset=\"https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a2-300x197.png 300w, https:\/\/www.inetmar.com\/blog\/wp-content\/uploads\/2024\/04\/a2.png 765w\" sizes=\"auto, (max-width: 586px) 100vw, 586px\" \/><br \/>\nMitM Sald\u0131r\u0131lar\u0131ndan Korunma Y\u00f6ntemleri<\/strong><\/h2>\n<p>MitM sald\u0131r\u0131lar\u0131n\u0131n kullan\u0131c\u0131lar taraf\u0131ndan fark edilmesi olduk\u00e7a zordur. Bundan dolay\u0131 sald\u0131r\u0131 ile kar\u015f\u0131la\u015fmamak i\u00e7in \u00f6nlem almal\u0131 ve ki\u015fisel verilerinizin korunmas\u0131n\u0131 sa\u011flamal\u0131s\u0131n\u0131z. Bireyler gibi \u015firketlerin de bu sald\u0131r\u0131dan korunmak i\u00e7in alabilecekleri \u00f6nlemler bulunur. Bunlar aras\u0131nda vir\u00fcs koruma program\u0131n\u0131n cihaza y\u00fcklenmesi ilk tercih olabilir.<\/p>\n<p>Wi-Fi kullan\u0131m\u0131n\u0131 a\u00e7\u0131k a\u011flar \u00fczerinden de\u011fil kendi a\u011f\u0131n\u0131z \u00fczerinden yapmal\u0131s\u0131n\u0131z. \u00c7ok fakt\u00f6rl\u00fc kimlik do\u011frulama sistemlerini kullanman\u0131z da bu sald\u0131r\u0131 t\u00fcr\u00fcnden korunabilmenizde etkili olmaktad\u0131r. <strong>MitM<\/strong> <strong>sald\u0131r\u0131lar\u0131ndan korunma y\u00f6ntemleri<\/strong> aras\u0131nda kendi Wi-Fi \u015fifrenizin tahmin edilemeyecek \u015fekilde d\u00fczenlenmesi yer al\u0131r. Parola, \u015fifre gibi normalde istenmeyen bilgilerinizi isteyen e-postalar\u0131 cevaplamamal\u0131s\u0131n\u0131z. Bu \u015fekilde sald\u0131r\u0131lardan korunman\u0131z m\u00fcmk\u00fcn olacakt\u0131r.<\/p>\n<p>Daha fazla i\u00e7erik i\u00e7in <a href=\"https:\/\/www.inetmar.com\/blog\/\" target=\"_blank\" rel=\"noopener\">blog<\/a> sayfam\u0131z\u0131 incelemeyi unutmay\u0131n!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Man in the middle T\u00fcrk\u00e7esi ortadaki adam sald\u0131r\u0131s\u0131 \u015feklinde olup siber sald\u0131r\u0131lar aras\u0131nda yer al\u0131r. A\u011fda iki ba\u011flant\u0131 aras\u0131na girilmesi, iki ba\u011flant\u0131 aras\u0131ndaki ileti\u015fimin dinlenmesi ve de\u011fi\u015ftirilebilmesi bu sald\u0131r\u0131y\u0131 a\u00e7\u0131klayan durumlard\u0131r. Bu sald\u0131\u011f\u0131 t\u00fcr\u00fcnde a\u011fdaki&#46;&#46;&#46;<\/p>\n","protected":false},"author":2,"featured_media":7308,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[],"class_list":["post-7307","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-genel"],"_links":{"self":[{"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/posts\/7307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/comments?post=7307"}],"version-history":[{"count":11,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/posts\/7307\/revisions"}],"predecessor-version":[{"id":9579,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/posts\/7307\/revisions\/9579"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/media\/7308"}],"wp:attachment":[{"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/media?parent=7307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/categories?post=7307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inetmar.com\/blog\/wp-json\/wp\/v2\/tags?post=7307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}