Yersinia, a framework for layer 2 attacks

From: Yersinia Authors (yersinia_at_wasahero.org)
Date: 04/01/05

  • Next message: Anurag Joshi: "Accessing Winxp shares"
    Date: Fri, 1 Apr 2005 14:47:59 +0200
    To: full-disclosure@lists.grok.org.uk
    
    

    Hi,
    we are pleased to announce the release of Yersinia, a framework for (mainly) layer 2
    attacks. The tool has been presented in BlackHat Europe 2005, so if any of you
    could attend the conference will know what it is about.

    Yersinia implements several attacks for the following protocols: Spanning
    Tree (STP), Cisco Discovery (CDP), Dynamic Host Configuration (DHCP), Hot Standby Router (HSRP), Dynamic
    Trunking (DTP), 802.1q and VLAN Trunking (VTP), helping the pen-tester in
    different tasks, e.g:

    - Becoming the root role in the Spanning Tree
    - Creating virtual CDP neighbors
    - Setting up rogue DHCP Servers
    - Becoming the active router in a HSRP scenario
    - Enabling trunk
    - Performing ARP spooing over VLAN Hopping
    - Adding/deleting VLANs (via VTP)
    - more..

    It is a multithreaded application with three main modes: command line, network
    client and ncurses GUI, allowing multiple users to launch multiple attacks
    simultanously.

    Besides, you can decode some Cisco propietary protocols like DTP or
    VTP!!

    You can download it from http://yersinia.sf.net and send your doubts,
    questions, bugs or greetings to yersinia@wasahero.org.

    Best regards and happy trails:)

    David Barroso Berrueta
    Alfredo Andres Omella


  • Next message: Anurag Joshi: "Accessing Winxp shares"

    Relevant Pages

    • [Full-disclosure] Yersinia, a framework for layer 2 attacks
      ... Yersinia implements several attacks for the following protocols: ... Performing ARP spooing over VLAN Hopping ... allowing multiple users to launch multiple attacks ...
      (Full-Disclosure)
    • Re: Stopping Arp poison attacks
      ... In addition to the good suggestion you have already received on using Dynamic ARP Inspection on Cisco Catalyst switches, here is another one that I have recommended to clients (since it is so trivial to inject MiTM attacks). ... place all of your Administrative users in an "Administrative workstation" VLAN. ... You have an option to go with a managed service or an enterprise software. ...
      (Pen-Test)
    • RE: [fw-wiz] VLAN Security
      ... > VLAN implementations as a security measure? ... > provide ISP services across this cloud. ... susceptible to "hopping" attacks. ...
      (Firewall-Wizards)
    • Re: finding layer 2 network devices
      ... maybe yersinia helps, which implements some layer2 ... attacks. ... it's also on the pentoo livecd: http://www.netsc.ch/pentoo/ ...
      (Pen-Test)