Re: Windows 2000 Static arp not static

From: Anthony Kim (Anthony.Kim@VW.COM)
Date: 02/24/03

  • Next message: Thane Walkup: "RE: MS Software Update Service"
    Date: Mon, 24 Feb 2003 14:16:43 -0600
    From: Anthony Kim <Anthony.Kim@VW.COM>
    To: focus-ms@securityfocus.com
    
    

    On Sun, Feb 16, 2003, shannong wrote:

    > The MAC address table mappings on switches have absolutely no
    > effect on this. The switch still sees the offending machine as
    > having the correct MAC address and the victim as having the
    > correct MAC address. This exploit works due to the ARP cache
    > poisoning of the victim as discussed in this thread.

    That's why you "lock" the tables on the switches if you really
    have to.

    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_5_5/cnfg_gd/sec_port.pdf
    http://www.cisco.com/en/US/netsol/ns110/ns170/ns171/ns128/networking_solutions_implementation_white_paper09186a008014870f.shtml

    If your threat model is such that you are considering static arp
    tables on each host, you will have to consider alternatives that
    are manageable.

    > You prevent this from happening like you do other exploits. Use an IDS.
    > One that detects these ARP flip-flops.
    >
    > -Shannon

    IDS will not "prevent this from happening".

    I wrote:

    > Most people would lock arp tables on the switch and not on the
    > host. If you're relying on MS-technology only, you probably have
    > a boatload of other problems to take care of... ;-)



    Relevant Pages

    • Re: MAC address spoofing - conflict?
      ... Switches have port/MAC mappings in memory. ... Duplicate IP addresses, problems such as dropped packets, arp floods, etc. ... Duplicate MAC addresses, Different IPs, no problem. ... Cenzic Hailstorm finds vulnerabilities fast. ...
      (Pen-Test)
    • RE: [Full-Disclosure] Re: Cain and Abel
      ... Static ARP entries on a server should be enough to prevent ... switches to prevent against MAC address spoofing. ...
      (Full-Disclosure)
    • Re: LynxOS 2.3 - networking issues
      ... so you get an ARP war. ... You may be on to something there with the "ARP War" comment. ... I'm thinking of another possibility: we use 3com switches. ... manufacturers have been recycling old MAC addresses for several years ...
      (comp.os.lynx)
    • Re: Static IP outside of router DHCP range
      ... Unfortunately my 8 clients are little $50 boxes with an Ethernet port and yellow, red, and white outputs for composite NTSC video and stereo audio, but no provisions whatsoever to flash their NVRAM. ... So I have no way to either reserve IP addresses based on Mac addresses, nor do I have a way to set them up as static. ... I still am wondering if my Netgear switches truly have any "memory" of the ports associated with specific IP addresses of the connected clients, as they have no reset or reboot function as far as I know. ...
      (alt.comp.hardware.pc-homebuilt)
    • RE: Caching a sniffer
      ... and I've just seen a new source MAC ... I looked through some old docs on Cisco switches. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)