Re: Locating switches in a multi-layer switching environment



Hi Jon,

Assume it's Cisco we're talking about? If so CDP would be helpful in
this situation.

Here is a previous thread, old but useful
http://seclists.org/pen-test/2003/May/0124.html

Also, give ICMP and SNMP a shot

cheers
Ivan

On 3/18/07, Jon R. Kibler <Jon.Kibler@xxxxxxxx> wrote:
Hi,

A network recon question: When pen testing an environment that deploys multi-layer switching, how can one reliably map the network and the relative location of all of the switches?

Add to this VLANS... How can you map VLANs that are on the network, especially if your access is but on one VLAN, and that VLAN is different than the switch management VLAN?

Thoughts, tools, tricks, white papers, etc. appreciated.

THANKS!
Jon Kibler
--
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC USA
(843) 849-8214



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Locating switches in a multi-layer switching environment
    ... A network recon question: When pen testing an environment that deploys multi-layer switching, how can one reliably map the network and the relative location of all of the switches? ... How can you map VLANs that are on the network, especially if your access is but on one VLAN, and that VLAN is different than the switch management VLAN? ...
    (Pen-Test)
  • Re: Locating switches in a multi-layer switching environment
    ... behind the floor switch in the one vlan. ... but is only visible on the management VLAN. ... Discover the location of every switch in the network. ... > Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: Clueless firewall configuration ?
    ... "drop" an IDS on a VLAN without adding network taps or other tricks. ... Having untrusted traffic on your core switch can cause the ... VLAN hopping attacks. ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • Re: ERS 8600, simple setup, IP, VLANs, etc.
    ... management port is just used to hang an IP address to. ... associated with an interface, such as a VLAN. ... fairly functionally homogenous network), but something that is ... or OS virtuallization - except that networks have been doing this kind of ...
    (comp.dcom.sys.nortel)
  • Re: MS Windows through QEMU
    ... create a new Network Interface Card and connect it to ... VLAN 'n' ... -serial dev redirect the serial port to char device 'dev' ...
    (Fedora)