Re: protecting DHCP servers

From: Akop Pogosian (akopps@CSUA.Berkeley.EDU)
Date: 05/18/02


Date: Fri, 17 May 2002 19:14:13 -0700
From: Akop Pogosian <akopps@CSUA.Berkeley.EDU>
To: focus-linux@securityfocus.com

On Fri, May 17, 2002 at 06:22:54PM -0700, Seth Arnold wrote:
<snip>

> Akop, yes, an attacker can spoof a source 0.0.0.0 in order to attack
> your dhcp server, and generally, the only way to prevent this is some
> level of sanity checking IPs based on the _interfaces_ the packet came
> in through.
>
> e.g., if your dhcp server has two NICs:
>
> eth0 is connected to the untrusted network
> eth1 is connected to trusted subnet

Actually, both "trusted" subnets are connected to the internet using
other routers to which I don't really have access. So, this solution
won't work. I call them trusted only because I "trust" that no
computer on those subnets will try to exploit anything on the server.

-akop



Relevant Pages

  • Re: protecting DHCP servers
    ... is it possible for an attacker who comes from ... > outside of the trusted subnets to which dhcp server connects ... Block it at your border router, ...
    (Focus-Linux)
  • Re: RRAS (2k3 server): dial-up clients cant authentificate
    ... DHCP server is on the same computer. ... RRAS use static adress ... In local network are two routed subnets 192.168.0.0, ... > In local network are two routed subnets 192.168.0.0, ...
    (microsoft.public.windows.server.general)
  • Re: DHCP for various subnets
    ... consider when providing a DHCP server for servicing various subnets? ... A "scope" for each such subnet. ... not unless you use all three subnets on the same "broadcast domain" ...
    (microsoft.public.windows.server.active_directory)
  • Re: dhcp server - one mac on multiple subnets
    ... The problem is that my setup should work for a relay agent with option 82 support. ... The network topology looks like this (with some 20 subnets): ... A dhcp server with support for this, can based on this information give the client the appropriate ip address. ... Either the router is just doing dhcp relaying withoutoption 82 support, or isc dhcp server does not support option 82, but I think isc dhcpd does. ...
    (Debian-User)
  • Re: DHCP Scopes Delegation
    ... > reservations for several remote sites. ... How can I delegate certain subnets to field ... > addresses, etc.) within certain, delegated DHCP scopes? ... > these subnets are on 1 DHCP server. ...
    (microsoft.public.win2000.active_directory)