{"id":33199,"date":"2022-04-11T17:08:31","date_gmt":"2022-04-11T14:08:31","guid":{"rendered":"https:\/\/www.natro.com\/blog\/?p=33199"},"modified":"2022-04-12T11:30:52","modified_gmt":"2022-04-12T08:30:52","slug":"mitm-ortadaki-adam-saldirisi-nedir","status":"publish","type":"post","link":"https:\/\/www.natro.com\/blog\/mitm-ortadaki-adam-saldirisi-nedir\/","title":{"rendered":"MitM (Ortadaki Adam) Sald\u0131r\u0131s\u0131 Nedir, Nas\u0131l Korunabilirsiniz?"},"content":{"rendered":"\n<p>Dijital d\u00fcnyada ileti\u015fim olanaklar\u0131n\u0131n geli\u015fmesi beraberinde yeni risk alanlar\u0131 getiriyor. Dijital d\u00fcnyada ileti\u015fim kurarken bilgisayar korsanlar\u0131n\u0131n ve k\u00f6t\u00fc niyetli yaz\u0131l\u0131mlar\u0131n ileti\u015fimin g\u00fcvenli\u011fini her an tehdit edebilece\u011fini unutmamak gerekir. K\u00f6keni y\u0131llar \u00f6ncesine dayanmakla birlikte g\u00fcn\u00fcm\u00fczde ad\u0131n\u0131 s\u0131k\u00e7a duyuran Man in the Middle (MitM\/Ortadaki Adam), hem internetin ki\u015fisel kullan\u0131m\u0131 hem i\u015fletmeler a\u00e7\u0131s\u0131ndan tetikte olmak gereken bir siber sald\u0131r\u0131 \u00e7e\u015fididir. Peki MitM nedir, nas\u0131l meydana gelir, korunmak i\u00e7in neler yap\u0131labilir?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-temel-hatlariyla-mitm\"><span id=\"temel-hatlariyla-mitm\"><strong>Temel Hatlar\u0131yla MitM<\/strong><\/span><\/h2>\n\n\n\n<p>Ortadaki adam sald\u0131r\u0131s\u0131 (MITM sald\u0131r\u0131s\u0131), bir siber sald\u0131rgan\u0131n \u201cdo\u011frudan ileti\u015fim kurduklar\u0131n\u0131 sanan\u201d iki taraf aras\u0131ndaki ileti\u015fimi kendine aktard\u0131\u011f\u0131 ve muhtemelen de\u011fi\u015ftirdi\u011fi bir siber sald\u0131r\u0131d\u0131r. Bu durum sald\u0131rgan\u0131n ileti\u015fimi iletmesine, dinlemesine ve hatta her bir taraf\u0131n s\u00f6ylediklerini de\u011fi\u015ftirmesine olanak tan\u0131r. Ortadaki adam sald\u0131r\u0131lar\u0131, insanlar, istemciler ve sunucular aras\u0131nda gizlice dinlemeyi m\u00fcmk\u00fcn k\u0131lar. Bu, web sitelerine HTTPS ba\u011flant\u0131lar\u0131n\u0131, di\u011fer SSL\/TLS ba\u011flant\u0131lar\u0131n\u0131, Wi-Fi a\u011f ba\u011flant\u0131lar\u0131n\u0131 ve daha fazlas\u0131n\u0131 i\u00e7erebilir.<\/p>\n\n\n\n<h2 id=\"mitm-saldiri-ornegi\" class=\"wp-block-heading\"><strong>MitM Sald\u0131r\u0131 \u00d6rne\u011fi<\/strong><\/h2>\n\n\n\n<p>Sizin ve bir i\u015f arkada\u015f\u0131n\u0131z\u0131n g\u00fcvenli bir mesajla\u015fma platformu \u00fczerinden ileti\u015fim kurdu\u011funuzu hayal edin. Sald\u0131rgan, gizlice dinlemek ve i\u015f arkada\u015f\u0131n\u0131za sizden yanl\u0131\u015f bir mesaj iletmek i\u00e7in konu\u015fmay\u0131 kesmek istiyor. Muhtemelen a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izleyebiliyor:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>\u0130lk olarak, i\u015f arkada\u015f\u0131n\u0131zdan ortak anahtar istiyorsunuz. Arkada\u015f\u0131n\u0131z size genel anahtar\u0131n\u0131 g\u00f6nderirse ve sald\u0131rgan onu ele ge\u00e7irebilirse, ortadaki adam sald\u0131r\u0131s\u0131 ba\u015flayabilir.<\/li><li>Sald\u0131rgan size, i\u015f arkada\u015f\u0131n\u0131zdan geliyormu\u015f gibi g\u00f6r\u00fcnen ancak bunun yerine sald\u0131rgan\u0131n ortak anahtar\u0131n\u0131 i\u00e7eren sahte bir mesaj g\u00f6nderir.<\/li><li>A\u00e7\u0131k anahtar\u0131n i\u015f arkada\u015f\u0131n\u0131za ait oldu\u011funa inanan siz, mesaj\u0131n\u0131z\u0131 sald\u0131rgan\u0131n anahtar\u0131yla \u015fifreler ve \u015fifrelenmi\u015f mesaj\u0131 \u201ci\u015f arkada\u015f\u0131n\u0131za\u201d (asl\u0131nda sald\u0131rgana) geri g\u00f6nderirsiniz.<\/li><li>Sald\u0131rgan, mesaj\u0131 tekrar ele ge\u00e7irir, kendi \u00f6zel anahtar\u0131n\u0131 kullanarak de\u015fifre eder, de\u011fi\u015ftirir ve ilk ba\u015fta size g\u00f6ndermeye \u00e7al\u0131\u015fan i\u015f arkada\u015f\u0131n\u0131zdan ele ge\u00e7irilen ortak anahtar\u0131 kullanarak mesaj\u0131 yeniden \u015fifreler.<\/li><li>\u0130\u015f arkada\u015f\u0131n\u0131z da \u015fifrelenmi\u015f mesaj\u0131 inceledi\u011finde, mesaj\u0131n sizden geldi\u011fine inan\u0131r.<\/li><li>\u0130\u015f arkada\u015f\u0131n\u0131za bir sald\u0131rgan taraf\u0131ndan ele ge\u00e7irilen bir mesaj g\u00f6ndermi\u015f olursunuz.<\/li><li>\u201cMerhaba [i\u015f arkada\u015f\u0131m], l\u00fctfen anahtar\u0131n\u0131 g\u00f6nderir misin?\u201d<\/li><li>Sald\u0131rgan mesaj\u0131 i\u015f arkada\u015f\u0131n\u0131za iletir, i\u015f arkada\u015f\u0131n\u0131z ortadaki bir adam oldu\u011funu s\u00f6yleyemez.<\/li><li>Siz [Sald\u0131rgan] \u201cMerhaba, l\u00fctfen bana anahtar\u0131n\u0131 g\u00f6nderir misin?\u201d<\/li><li>\u0130\u015f arkada\u015f\u0131 \u015fifreleme anahtar\u0131yla yan\u0131t veriyor.<\/li><li>Sald\u0131rgan, i\u015f arkada\u015f\u0131n\u0131z\u0131n anahtar\u0131n\u0131 kendisininkiyle de\u011fi\u015ftirir ve i\u015f arkada\u015f\u0131n\u0131z\u0131n anahtar\u0131 oldu\u011funu iddia ederek mesaj\u0131 size iletir.<\/li><li>Bir mesaj\u0131, i\u015f arkada\u015f\u0131n\u0131z\u0131n anahtar\u0131 oldu\u011funa inand\u0131\u011f\u0131n\u0131z bir \u015feyle \u015fifrelersiniz, sadece i\u015f arkada\u015f\u0131n\u0131z\u0131n okuyabilece\u011fini d\u00fc\u015f\u00fcn\u00fcrs\u00fcn\u00fcz.<\/li><li>Siz \u201c\u015eifremiz XYZ\u201d [sald\u0131rgan\u0131n anahtar\u0131yla \u015fifrelenmi\u015ftir]<\/li><li>Mesaj sald\u0131rgan\u0131n anahtar\u0131yla \u015fifrelendi\u011finden, \u015fifresini \u00e7\u00f6zer, okur ve de\u011fi\u015ftirir, meslekta\u015f\u0131n\u0131z\u0131n anahtar\u0131yla yeniden \u015fifreler ve mesaj\u0131 ba\u015fka bir yere iletirler.<\/li><\/ul>\n\n\n\n<p>Bu durumda hem siz hem i\u015f arkada\u015f\u0131n\u0131z mesaj\u0131n g\u00fcvenli oldu\u011funu d\u00fc\u015f\u00fcnerek ileti\u015fime devam edersiniz. Oysa ger\u00e7ekte, aran\u0131zda biri daha vard\u0131r: Ortadaki Adam! Bu \u201cortadaki adam\u201d k\u00f6t\u00fc niyetlidir, gizli kalmas\u0131 gereken bilgileri edinebilir. Farkl\u0131 bir niyeti varsa, \u00f6rne\u011fin aran\u0131zdaki ileti\u015fimi manip\u00fcle edebilir.<\/p>\n\n\n\n<p>Bu \u00f6rnek, taraflar\u0131n bir sald\u0131rgan\u0131n a\u00e7\u0131k anahtar\u0131 yerine birbirlerinin ortak anahtarlar\u0131yla ileti\u015fim kurmas\u0131n\u0131 sa\u011flayacak bir sistemin \u00f6nemini i\u015faret eder. G\u00fc\u00e7l\u00fc bilgi g\u00fcvenli\u011fi uygulamalar\u0131na sahip olmak yeterli de\u011fildir, MitM (Ortadaki adam) sald\u0131r\u0131lar\u0131 riskini her zaman kontrol etmeniz gerekir.<\/p>\n\n\n\n<h2 id=\"mitm-saldirilari-tehlikeli-mi\" class=\"wp-block-heading\"><strong>MitM Sald\u0131r\u0131lar\u0131 Tehlikeli mi?<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"800\" height=\"528\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam.jpg\" alt=\"\" class=\"wp-image-33210\" srcset=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam.jpg 800w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-300x198.jpg 300w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-768x507.jpg 768w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-380x251.jpg 380w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-760x502.jpg 760w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-600x396.jpg 600w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p>Ortadaki adam sald\u0131r\u0131lar\u0131 tehlikelidir ve genellikle iki amac\u0131 vard\u0131r. Bunlar\u0131n biri ya da ikisi birden sald\u0131r\u0131n\u0131n amac\u0131 olabilir:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Hassas verilere ve ki\u015fisel bilgilere eri\u015fim kazanmak<\/li><li>\u0130letilen bir mesaj\u0131n i\u00e7eri\u011fini i\u015flemek<\/li><\/ul>\n\n\n\n<p>Sald\u0131rgan MitM sald\u0131r\u0131s\u0131 ile \u015funlara eri\u015fim sa\u011flamay\u0131 hedefler:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Kimlik h\u0131rs\u0131zl\u0131\u011f\u0131 i\u00e7in ki\u015fisel olarak tan\u0131mlanabilir bilgiler (PII) ve di\u011fer hassas bilgiler<\/li><li>\u00c7evrimi\u00e7i banka hesaplar\u0131na yetkisiz eri\u015fim elde etmek i\u00e7in halka a\u00e7\u0131k bir Wi-Fi a\u011f\u0131nda oturum a\u00e7ma kimlik bilgileri<\/li><li>Bir e-ticaret sitesinde kredi kart\u0131 numaralar\u0131n\u0131 \u00e7almak<\/li><li>Kamuya a\u00e7\u0131k Wi-Fi eri\u015fim noktalar\u0131ndaki trafi\u011fi, yasal web sitelerinden k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m bar\u0131nd\u0131ran sitelere y\u00f6nlendirmek.<\/li><\/ul>\n\n\n\n<p>MITM sald\u0131r\u0131lar\u0131n\u0131n ortak hedefleri web siteleri ve e-postalard\u0131r. E-postalar varsay\u0131lan olarak \u015fifreleme kullanmaz, bu da sald\u0131rgan\u0131n g\u00f6nderenden gelen e-postalar\u0131 yaln\u0131zca oturum a\u00e7ma kimlik bilgileriyle ele ge\u00e7irmesine ve yan\u0131ltmas\u0131na olanak tan\u0131r.<\/p>\n\n\n\n<h2 id=\"mitm-ile-sniffing-koklama-arasindaki-farklar\" class=\"wp-block-heading\"><strong>MitM ile Sniffing (Koklama) Aras\u0131ndaki Farklar<\/strong><\/h2>\n\n\n\n<p>\u0130nternet protokollerinin do\u011fas\u0131 gere\u011fi, internete g\u00f6nderilen bilgilerin \u00e7o\u011funa genel olarak eri\u015filebilir. Bir yerel a\u011fa (LAN) ba\u011fland\u0131\u011f\u0131n\u0131zda, di\u011fer t\u00fcm bilgisayarlar veri paketlerinizi g\u00f6rebilir. Bir sald\u0131rgan sizinle ayn\u0131 a\u011fdayken, verileri okumak i\u00e7in bir dinleyici kullanabilir ve istemciniz ile sunucu (istemciniz ve sunucu dahil) aras\u0131ndaki herhangi bir bilgisayara eri\u015febiliyorsa ileti\u015fiminizi dinlemelerine izin verebilir.<\/p>\n\n\n\n<p>Ortadaki adam sald\u0131r\u0131s\u0131nda, sald\u0131rgan sizi veya bilgisayar\u0131n\u0131z\u0131 kendi bilgisayarlar\u0131na ba\u011flanman\u0131z i\u00e7in kand\u0131r\u0131r. Bu, ba\u011flanmak istedi\u011finiz yerin onlar oldu\u011funa inanman\u0131z\u0131 sa\u011flar. Daha sonra as\u0131l hedefinize ba\u011flan\u0131p sizmi\u015fsiniz gibi davran\u0131rlar, istenirse bilgileri her iki \u015fekilde aktar\u0131r ve de\u011fi\u015ftirirler. Bilgi de\u011fi\u015ftirilebildi\u011fi i\u00e7in bu \u00e7ok daha b\u00fcy\u00fck bir siber g\u00fcvenlik riskidir.<\/p>\n\n\n\n<p>Siber g\u00fcvenlik default (varsay\u0131lan olarak) \u015fifrelemeye y\u00f6neldik\u00e7e, sniffing (koklama) ve MitM (ortadaki adam) sald\u0131r\u0131lar\u0131 daha tehditkar hale geliyor. Sald\u0131rganlar, kullan\u0131c\u0131lar\u0131 kand\u0131rmak veya ortadaki adam olmak i\u00e7in kriptografik protokollerdeki zay\u0131fl\u0131klardan yararlanmada \u00e7e\u015fitli teknikler kullanabilir. Ortadaki bir adam\u0131n ileti\u015fiminizi engellemesini \u00f6nlemek i\u00e7in g\u00fcvenli bir ba\u011flant\u0131 yeterli de\u011fildir.<\/p>\n\n\n\n<h2 id=\"mitm-saldirilari-nerede-olur\" class=\"wp-block-heading\"><strong>MitM Sald\u0131r\u0131lar\u0131 Nerede Olur?<\/strong><\/h2>\n\n\n\n<p>Ortadaki adam sald\u0131r\u0131lar\u0131n\u0131n bir\u00e7ok t\u00fcr\u00fc vard\u0131r ancak genel olarak bunlar d\u00f6rt \u015fekilde ger\u00e7ekle\u015fir:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Genel a\u011flar: Herhangi bir genel a\u011fa ba\u011fland\u0131\u011f\u0131n\u0131zda asl\u0131nda b\u00fcy\u00fck risk alt\u0131ndas\u0131n\u0131z. \u00d6rnek olarak havaalanlar\u0131nda veya kafelerde, eri\u015fim k\u0131s\u0131tlamas\u0131 olmayan herhangi bir a\u011fda halka a\u00e7\u0131k Wi-Fi ba\u011flant\u0131lar\u0131 verilebilir. Burada bir sald\u0131rgan\u0131n ortadaki adam olmas\u0131 en kolay\u0131d\u0131r \u00e7\u00fcnk\u00fc bir\u00e7ok MitM tekni\u011finin en iyi \u00e7al\u0131\u015ft\u0131\u011f\u0131 yerler yerel alan ve Wi-Fi a\u011flar\u0131d\u0131r.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Bilgisayar\u0131n\u0131z: \u0130nternet ba\u011flant\u0131n\u0131z\u0131 izleyen ve de\u011fi\u015ftiren sitelere sizi \u00e7ekerek ba\u011flant\u0131n\u0131z\u0131 ele ge\u00e7iren k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar ile MitM sald\u0131r\u0131s\u0131 ger\u00e7ekle\u015ftirilebilir.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Router: Routerlar (y\u00f6nlendiriciler) genellikle \u0130nternet servis sa\u011flay\u0131c\u0131n\u0131z taraf\u0131ndan sa\u011flan\u0131r ve varsay\u0131lan g\u00fcvenlik ayarlar\u0131na sahiptir. Bu, bir\u00e7ok y\u00f6nlendiricinin varsay\u0131lan oturum a\u00e7ma kimlik bilgilerine (y\u00f6netici\/parola gibi) veya bilinen bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131na sahip olabilecek g\u00fcncel olmayan bellenime (firmware) sahip oldu\u011fu anlam\u0131na gelir.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>Web sunucusu: Sald\u0131rgan, ileti\u015fim kurmay\u0131 ama\u00e7lad\u0131\u011f\u0131n\u0131z orijinal web sunucusuna eri\u015fim kazan\u0131r ve MitM sald\u0131r\u0131s\u0131 ger\u00e7ekle\u015ftirir.<\/li><\/ul>\n\n\n\n<h2 id=\"mitm-ortadaki-adam-saldirisi-nasil-olur\" class=\"wp-block-heading\"><strong>MitM (Ortadaki Adam) Sald\u0131r\u0131s\u0131 Nas\u0131l Olur?<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"800\" height=\"508\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1.jpg\" alt=\"\" class=\"wp-image-33209\" srcset=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1.jpg 800w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1-300x191.jpg 300w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1-768x488.jpg 768w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1-380x241.jpg 380w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1-760x483.jpg 760w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/04\/mtm-ortadaki-adam-1-600x381.jpg 600w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p>MitM \u2013 Ortadaki adam sald\u0131r\u0131s\u0131 \u00fc\u00e7 a\u015famaya ayr\u0131labilir:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Birinci a\u015fama: Sald\u0131r\u0131y\u0131 ger\u00e7ekle\u015ftirmek i\u00e7in bir konuma eri\u015fim sa\u011flama<\/li><li>\u0130kinci a\u015fama: Ortadaki adam olma<\/li><li>\u00dc\u00e7\u00fcnc\u00fc a\u015fama: Gerekirse \u015fifrelemenin \u00fcstesinden gelme<\/li><\/ul>\n\n\n\n<p>Sald\u0131rgan, sizinle istedi\u011finiz hedef aras\u0131na girdi\u011finde art\u0131k \u201cortadaki adam\u201d olmu\u015ftur. Bunun ba\u015far\u0131l\u0131 olmas\u0131 i\u00e7in bir veya birka\u00e7 farkl\u0131 yan\u0131ltma\/kand\u0131rma\/ spoofing sald\u0131r\u0131 tekni\u011fi ile bilgisayar\u0131n\u0131z\u0131 kand\u0131rmaya \u00e7al\u0131\u015facakt\u0131r.<\/p>\n\n\n\n<h3 id=\"mitm-saldirilarinda-kullanilan-bazi-teknikler\" class=\"wp-block-heading\"><strong>MitM Sald\u0131r\u0131lar\u0131nda Kullan\u0131lan Baz\u0131 Teknikler<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>ARP Spoofing: ARP (veya Adres \u00c7\u00f6z\u00fcmleme Protokol\u00fc), bir cihaz\u0131n fiziksel adresini (MAC adresi veya medya eri\u015fim kontrol adresi) ve yerel alan a\u011f\u0131nda ona atanan IP adresini \u00e7evirir. ARP kimlik sahtekarl\u0131\u011f\u0131 kullanan bir sald\u0131rgan, ba\u011flant\u0131lar\u0131n\u0131 cihazlar\u0131na yeniden y\u00f6nlendirmek i\u00e7in yerel alan a\u011f\u0131na yanl\u0131\u015f bilgiler enjekte etmeyi ama\u00e7lar.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>IP Spoofing: IP sahtekarl\u0131\u011f\u0131, bir makinenin farkl\u0131 bir IP adresine, genellikle ba\u015fka bir makineyle ayn\u0131 adrese sahipmi\u015f gibi davranmas\u0131d\u0131r. Kendi ba\u015f\u0131na, IP sahtekarl\u0131\u011f\u0131 bir ortadaki adam sald\u0131r\u0131s\u0131 de\u011fildir, ancak TCP dizi tahmini ile birle\u015ftirildi\u011finde bir sald\u0131r\u0131 haline gelir. Genel olarak \u0130nternet ba\u011flant\u0131lar\u0131 TCP\/IP (\u0130letim Kontrol Protokol\u00fc \/ \u0130nternet Protokol\u00fc) ile kurulur.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>DNS Spoofing: ARP s\u0131zd\u0131rma ve IP s\u0131zd\u0131rma, sald\u0131r\u0131n\u0131n sizinle ayn\u0131 yerel alan a\u011f\u0131na ba\u011flanmas\u0131na dayan\u0131r. DNS sahtekarl\u0131\u011f\u0131 ile herhangi bir yerden bir sald\u0131r\u0131 gelebilir. DNS sahtekarl\u0131\u011f\u0131, savunmas\u0131z bir DNS \u00f6nbelle\u011fine dayand\u0131\u011f\u0131ndan genellikle daha zordur. Ancak DNS sahtekarl\u0131\u011f\u0131 ba\u015far\u0131l\u0131 olursa \u00e7ok say\u0131da insan\u0131 etkileyebilir.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>HTTPS Spoofing: Web taray\u0131c\u0131 sahtekarl\u0131\u011f\u0131, bir sald\u0131rgan\u0131n ba\u011flanmak istedi\u011finiz alan ad\u0131na \u00e7ok benzeyen bir alan ad\u0131n\u0131 kaydetti\u011fi bir yaz\u0131m hatas\u0131 bi\u00e7imidir. Ard\u0131ndan, kimlik av\u0131 gibi di\u011fer teknikleri kullanmak i\u00e7in yanl\u0131\u015f URL\u2019yi teslim ederler. \u00d6rnek: faceboook.com<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>E-posta ele ge\u00e7irme, bir sald\u0131rgan\u0131n bir e-posta hesab\u0131n\u0131 ele ge\u00e7irmesi ve e-posta konu\u015fmalar\u0131n\u0131 \u201cdinleyerek\u201d sessizce bilgi toplamas\u0131d\u0131r. E-posta korsanl\u0131\u011f\u0131, e-postan\u0131n sahibi olan ve genellikle hedef odakl\u0131 kimlik av\u0131 i\u00e7in kullan\u0131lan yayg\u0131n bir metottur.<\/li><\/ul>\n\n\n\n<h3 id=\"mitm-saldirilarina-karsi-guvenlik-cozumleri\" class=\"wp-block-heading\"><strong>MitM Sald\u0131r\u0131lar\u0131na Kar\u015f\u0131 G\u00fcvenlik \u00c7\u00f6z\u00fcmleri<\/strong><\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-1024x768.jpg\" alt=\"\" class=\"wp-image-32848\" srcset=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-1024x768.jpg 1024w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-300x225.jpg 300w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-768x576.jpg 768w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-1536x1152.jpg 1536w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-380x285.jpg 380w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-800x600.jpg 800w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-1160x870.jpg 1160w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-600x450.jpg 600w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-760x570.jpg 760w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2-1600x1200.jpg 1600w, https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2022\/02\/ters-proxy-2.jpg 2000w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>MitM \u2013 Ortadaki adam sald\u0131r\u0131lar\u0131n\u0131n bir\u00e7ok t\u00fcr\u00fc vard\u0131r ve baz\u0131lar\u0131n\u0131n tespit edilmesi zordur. Ortadaki adam sald\u0131r\u0131lar\u0131na kar\u015f\u0131 en iyi \u00e7\u00f6z\u00fcm, onlar\u0131 \u00f6nlemektir. Bir sald\u0131rgan\u0131n a\u011f\u0131n\u0131za eri\u015fimi varsa ba\u011flant\u0131n\u0131z\u0131 ele ge\u00e7irmesini engellemek zor olsa da, ileti\u015fiminizin g\u00fc\u00e7l\u00fc bir \u015fekilde \u015fifrelenmesini sa\u011flayabilirsiniz.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Sanal \u00d6zel A\u011f (VPN): VPN\u2019ler, bir sald\u0131rgan\u0131n ileti\u015fimi okuma veya de\u011fi\u015ftirme yetene\u011fini s\u0131n\u0131rlayarak web trafi\u011finizi \u015fifreler.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>A\u011f izinsiz giri\u015f tespit sistemi (NIDS): NIDS, a\u011fdaki t\u00fcm cihazlardan gelen ve giden trafi\u011fi izlemek i\u00e7in bir a\u011f i\u00e7indeki stratejik noktalara yerle\u015ftirilir. T\u00fcm alt a\u011fda ge\u00e7en trafi\u011fin analizini ger\u00e7ekle\u015ftirir ve alt a\u011flarda ge\u00e7irilen trafi\u011fi bilinen sald\u0131r\u0131lar\u0131n kitapl\u0131\u011f\u0131na e\u015fle\u015ftirir. Bir sald\u0131r\u0131 tespit edildi\u011finde veya anormal davran\u0131\u015f bulundu\u011funda uyar\u0131 g\u00f6nderilebilir.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>G\u00fcvenlik Duvar\u0131: G\u00fc\u00e7l\u00fc bir g\u00fcvenlik duvar\u0131 yetkisiz eri\u015fimi engelleyebilir.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>\u0130ki fakt\u00f6rl\u00fc kimlik do\u011frulama: E-postalar\u0131n ele ge\u00e7irilmesini \u00f6nlemenin iyi bir yolu, parolan\u0131z\u0131n \u00f6tesinde ek bir kimlik do\u011frulama vekt\u00f6r\u00fc gerektiren iki fakt\u00f6rl\u00fc kimlik do\u011frulama kullanmakt\u0131r.<\/li><\/ul>\n\n\n\n<p>MitM dahil olmak \u00fczere siber g\u00fcvenli\u011fi ilgilendiren t\u00fcm konularda Natro.com \u00fczerinden destek alabilirsiniz. Alan\u0131nda deneyimli Natro teknik ekibi ki\u015fisel siteleriniz ya da i\u015fletmeleriniz i\u00e7in en etkili g\u00fcvenlik \u00e7\u00f6z\u00fcmlerini sunar.<\/p>\n","protected":false},"excerpt":{"rendered":"Dijital d\u00fcnyada ileti\u015fim olanaklar\u0131n\u0131n geli\u015fmesi beraberinde yeni risk alanlar\u0131 getiriyor. Dijital d\u00fcnyada ileti\u015fim kurarken bilgisayar korsanlar\u0131n\u0131n ve k\u00f6t\u00fc&hellip;\n","protected":false},"author":7,"featured_media":33208,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[53,652],"tags":[],"class_list":{"0":"post-33199","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-guvenlik","8":"category-nedir"},"_links":{"self":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts\/33199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/comments?post=33199"}],"version-history":[{"count":3,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts\/33199\/revisions"}],"predecessor-version":[{"id":33216,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts\/33199\/revisions\/33216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/media\/33208"}],"wp:attachment":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/media?parent=33199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/categories?post=33199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/tags?post=33199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}