Re: VLAN hopping - demonstration




On Wed, 18 Oct 2006, Ivan . wrote:

check these out

http://www.packetfactory.net/papers/VLAN-hopping/stake_wp.pdf
http://lists.grok.org.uk/pipermail/full-disclosure/2005-September/037252.html
http://www.sans.org/resources/idfaq/vlan.php

should get you started

Those documents show that vlan hopping doesn't work on properly configured switches.

On 10/18/06, dubaisans dubai <dubaisans@xxxxxxxxx> wrote:
How do you demonstrate VLAN hopping?. I am trying to show this to a customer who has mutliple DMZ segments configured as Layer2 VLANs on a Cisco 6500 switch. There is NO trunk port on this switch but DTP is turned on on all ports.

Is it enough to cascade another L2 switch on an access port [ say VLAN 100] of the 6509, connect a desktop on this second switch and send a packet with different VLAN ID [say VLAN 200] on the 6509.

Am I on the right track?

The right track would IMHO be to teach the customer how to configure his switch.

Ulric

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Strannge situation with two SRW224G4 and one Cisco 2950-12
    ... doesn't mean the vlan has been created. ... The em1 card of the BSD is connected into trunk port g3 of the first ... LinkSys SRW224G4 switch as described at scheme. ... So I suspect that problem is in Cisco switch configuration or IOS. ...
    (comp.dcom.sys.cisco)
  • Re: 470-48T switches can I do this?
    ... My fibers are going into the core, one is on the 172.16.x.x vlan while ... All MLT port members must be ... those that are used on the core switch. ...
    (comp.dcom.sys.nortel)
  • Re: Restart: VLAN question...
    ... Configure all ports except the Domain Controller as PVE ... Configure the Domain Controller port as the uplink ... you do the same thing on the Internet switch. ... PVE's are used between like switches to extend your VLAN topology across ...
    (comp.dcom.lans.ethernet)
  • Strannge situation with two SRW224G4 and one Cisco 2950-12
    ... LinkSys SRW224G4 switch as described at scheme. ... forwarding via another trunk port to second SRW224G4 and then to Cisco ... vlan40 is described in VLAN DB of all three switches. ... So I suspect that problem is in Cisco switch configuration or IOS. ...
    (comp.dcom.sys.cisco)
  • Re: 470-48T switches can I do this?
    ... My fibers are going into the core, one is on the 172.16.x.x vlan while ... All MLT port members must be ... those that are used on the core switch. ...
    (comp.dcom.sys.nortel)