Possible (or possibly painful) workaround for FreeBSD-SA-03:14.arp

From: Michael Sierchio (kudzu_at_tenebras.com)
Date: 09/24/03

  • Next message: Ruslan Ermilov: "Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp"
    Date: Wed, 24 Sep 2003 08:56:13 -0700
    To: security@freebsd.org
    
    

    Of course you should patch/upgrade, etc. A stopgap measure
    could be to use static ARP for a segment. I have done this
    for a long time with wireless hosts, since I'm in an urban
    environment with many visible nodes, some in autos, and
    ARP cache poisoning is a well-known DoS against wireless.

    You may find it extremely painful and less-than-useful to
    have static IP addrs, etc. for hosts.

    Here's a snippet of /usr/local/etc/rc.d/20-statarp.sh from
    my FreeBSD host (192.168.1.1) serving as a wireless router

    #! /bin/sh

    PATH=/usr/sbin:/sbin

    ifconfig wi0 -arp
    arp -d -a 2>&1 > /dev/null

    # wireless NICs

    arp -s 192.168.1.1 00:02:2d:0e:00:40 2>&1 > /dev/null
    arp -s 192.168.1.129 00:30:ab:14:11:46 2>&1 > /dev/null
    arp -s 192.168.1.130 00:30:ab:14:11:f6 2>&1 > /dev/null

    ###$# many entries deleted ...

    arp -s 192.168.1.195 00:30:ab:14:0f:89 2>&1 > /dev/null

    # end

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Ruslan Ermilov: "Re: FreeBSD Security Advisory FreeBSD-SA-03:14.arp"

    Relevant Pages

    • Re: hosts on bridged wlan can not reliably see each other
      ... all hosts on the wireless can get outside, ... packets transmitted, 3 packets received, 0.0% packet loss ... 05:40:28.486793 arp who-has 192.168.0.129 tell 192.168.0.12 ...
      (freebsd-current)
    • Re: cannot access a particular site (3rd time trying you guys)
      ... I searched HOSTS in sys32 drivers etc and found no ... The MN510 is not a router, just a wireless usb adaptor to ... There are no other computers using the MN510. ... >> registry and all the ie settings that the techs at HP ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: cannot access a particular site (3rd time trying you guys)
      ... Do other Laughlin Wireless subscribers have the same problem? ... Did you open HOSTS ... CWShredder (fix all) ... > There are no other computers using the MN510. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: hosts on bridged wlan can not reliably see each other
      ... all hosts on the wireless can get outside, ... Use tcpdump to track where the packets are visible. ... 05:40:28.486793 arp who-has 192.168.0.129 tell 192.168.0.12 ...
      (freebsd-current)
    • Network Setup Advice
      ... I'm trying to think of some ideas to set up this network nicely. ... Wireless (both hosts), capable of AP ... Bluetooth, capable of NAP, GN or whatever the setup would need. ...
      (comp.os.linux.networking)