Re: ATM Switch Vulnerabilities

From: Jose Nazario (jose@biocserver.BIOC.cwru.edu)
Date: 10/17/01


Date: Wed, 17 Oct 2001 15:17:32 -0400 (EDT)
From: Jose Nazario <jose@biocserver.BIOC.cwru.edu>
To: "Myron L. Cramer" <mcramer@wias.net>
Subject: Re: ATM Switch Vulnerabilities
Message-ID: <Pine.LNX.4.30.0110171512130.1050-100000@biocserver.BIOC.CWRU.Edu>

On Tue, 16 Oct 2001, Myron L. Cramer wrote:

> I would appreciate any links or information relative to ATM Switch
> vulnerabilities or risks, especially anything that works below the IP
> level. Thanks.

what kind of ATM? LANE? CLIP? pure ATM?

if its LANE, you can abuse the ARP table size and shove unicasts to the
BUS, leaking traffic, on some switches, especially edge devices. its not
pretty. Fore (now marconi) used to have some API code for doing ATM cells
from the ground up.

just some thoughts. also, a lot of Fore switches ran Solaris. you could
get in and abuse the switching tables there.

____________________________
jose nazario jose@cwru.edu
                           PGP: 89 B0 81 DA 5B FD 7E 00 99 C3 B2 CD 48 A0 07 80
                                       PGP key ID 0xFD37F4E5 (pgp.mit.edu)

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: MTU
    ... provider uses ATM, even though 1492 is the largest possible frame size. ... even better is to switch to a provider or plan that *doesn't* use ... PPPoE, but instead bridged ethernet with a MTU of 1500. ...
    (alt.os.linux.suse)
  • Re: Cisco 5002 question
    ... 1010 ATM switch installed in the bottom slots of the Catalyst ... Modules that support EtherChannel. ... switch requires a hardware upgrade. ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] Firewalling between T-1s, an ATM switch and a switched office
    ... > cisco switch which connects another office. ... > Can this work through ACL's at the ATM switch? ... > ACL's on source and destination IP's and ports? ... On that you emulate your "normal" Ethernet network. ...
    (Firewall-Wizards)
  • Re: Question on ATM w/ FreeBSD
    ... >with a DS3 card, then plug a PC running FreeBSD and Quagga, with a ... >the LS1010, then define a VC, switch it through the switch, ... >ATM on a DS3? ... New and Improved Yahoo! ...
    (freebsd-questions)
  • Re: Two vulnerabilities are founded,please confirm.
    ... The first one is Linux kernel IP ... over ATM clip_mkip dereference freed pointer,and the second is Linux ... kernel Filesystem Mount Dead Loop.Please check out the detailes about ... the vulnerabilities at the end of this Email. ...
    (Linux-Kernel)