Re: Layer 2 arp snooping without Layer 3?



Le jeudi 25 octobre 2007 à 10:44 +0300, Nikolaj a écrit :
Well you could poison one's cache but without you having an ip address
it will be pointless. [...] and the kernel will most likely discard
it). I think this is what will happen.

Not necessarily.
You can sniff traffic and send it back to userland applications using a
mechanism such as tuntap. On Linux, you can use ebtables framework to
route traffic back to IP stack, then Netfilter to another local IP
address.
You just have to send it somewhere you have an IP address, but it does
not have to be on the link you're sending your ARP cahce poisoning.


--
http://sid.rstack.org/
PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
Hi! I'm your friendly neighbourhood signature virus.
Copy me to your signature file and help me spread!

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Integer Promotions
    ... No, I disagree. ... assignment expression, because the assignment itself was the purpose of ... Casting the assignment to void, however, is pointless. ... necessary to do this in order to discard the value. ...
    (comp.lang.c)
  • Re: hiding a counter
    ... kernel if the application can find a time stamp that is in the future ... He is saying, and I am agreeing, that trying to enforce a license is ... So you are saying it is pointless to secure your property. ... The actual purpose of a door lock is to unambigously inform everybody ...
    (comp.unix.programmer)
  • Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3
    ... the process would be pointless. ... kernel people who were not keen on GPLv3 was fairly high. ...
    (Linux-Kernel)
  • Re: hiding a counter
    ... kernel if the application can find a time stamp that is in the future ... The reason to 'lock' a program is that the person writing the ... The honest people will pay even if there is no ... So you are saying it is pointless to secure your property. ...
    (comp.unix.programmer)
  • POSIX message queues, libmqueue: mq_open, mq_unlink
    ... name validity in the mq_open and mq_unlink. ... are pointless if the code in kernel depends on the valid name, ... kernel does not depend on them, because it will return an error anyway, ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)