Re: DoS of LAN via D-Link switches

From: Tarmo Mamers (tarmo_at_pobox.com)
Date: 03/29/05

  • Next message: GulfTech Security Research: "Multiple phpCoin Vulnerabilities"
    To: <bugtraq@securityfocus.com>
    Date: Wed, 30 Mar 2005 00:29:24 +0300
    
    

    > > From: Frank Bures [mailto:lisfrank@chem.toronto.edu]
    > > Sent: Tuesday, March 29, 2005 4:41 AM

    > > When user connects the same patch cable to two ports of the
    > > switch, the
    > > switch will ultimately bring down hierarchically higher
    > > branches of the
    > > LAN.

    > > Ours is a rather large LAN. One part of it is served by
    > > Extreme Networks
    > > switches. None of the SGI machines behind these switches
    > > were affected by
    > > the short. In fact no adverse effects were observed in that
    > > part of the
    > > LAN.

    This is natural behaviour of Ethernet ("natural" being dependent of your
    network design, of course :) and has nothing to do with D-Link or any other
    manufacturer.

    Some switches offer automatic port disabling feature if BPDU is received on
    a port defined as access port. All workstation ports should be defined as
    access ports for this to work. Workstations are not taking part of any
    Spanning Tree and they shouldn't generate any BPDUs and thus BPDUs shouldn't
    come into the switch from any access port. When you interconnect two switch
    ports defined as access ports, BPDUs generated by the switch reach another
    access port and trigger the disabling feature. This works in case or a
    single switch as well as between different switches as long as all your
    switches are Spanning Tree enabled.

    How the "short-circuit" affects specific switches depends how their unknown
    frame forwarding is configured and where they stand in a multi-tier switch
    topology.

    > > In my opinion, a switch should be immune to this admittedly insane
    > > manipulation. Otherwise, one can DoS the entire network just
    > > by shorting
    > > two RJ-45 network outlets in one's office together.

    Switches _are_ immune to insane manipulation if configured correctly.
    Excluding plugging out the power cord, unfortunately...

    -tarmo-


  • Next message: GulfTech Security Research: "Multiple phpCoin Vulnerabilities"

    Relevant Pages

    • portfast bpduguard..
      ... does portfast (on an access port) prevent BPDU from being ... At issue is that I do not have administrative access to lets say switch A, ...
      (comp.dcom.sys.cisco)
    • RE: IP address conflicts
      ... If you get a network vendor like Network Hardware Resale ... >> It's amazing how money will appear out of thin air if certain oxen get ... the switch you are suggesting I cannibalise uses the EtherToken ... When dealing with a bureaucracy I have found the most effective method is ...
      (freebsd-questions)
    • Re: ConnectComputer Problem
      ... I'm a little confused by your network configuration. ... Switch2 --- SBS Server ... switch has internet access all the time, the second switch has the client ... NICs ...
      (microsoft.public.windows.server.sbs)
    • Re: Help with long term network problem
      ... Using a CNET network switch connected to a CNet Wireless G router Model ... Having the chart listing all of the computers is a great start. ... /all" shows only an Intel 2200BG WiFi connection - no Ethernet is apparent. ...
      (microsoft.public.windowsxp.network_web)
    • Re: LAN ip subnet is moving off from a bigger enterprise
      ... The host company runs Cisco ... Connect your switch to this ... At the CBO the network is 10.23.1.x and the gateway ... WS1 WS3 SBS HP4000 ...
      (microsoft.public.windows.server.sbs)