Re: switch jamming

From: ALoR (Alor@iol.it)
Date: 01/31/02


Date: Thu, 31 Jan 2002 17:56:56 +0100
To: vuln-dev@securityfocus.com
From: ALoR <Alor@iol.it>

At 08.15 31-01-2002, you wrote:

>The Cisco switches at least can be secured against this, if you can
>live with the inconvenience. If you have one machine per port, you
>can configure the switch to learn the first MAC address it sees,
>and then not accept frames from any other address. This means
>that you can't move machines around or changes NICs without the
>switch admin resetting the MAC address for the affected ports. It also
>means that you can't chain multiple machines off of any ports
>configured that way, say via a hub.

this protection is useless if you use Arp poisoning without spoofing your
mac address.
since the targets are the arp cache of the victims and not the switch
itself, the port security feature can't block "fake arp replies" with
"legal" mac address.
then, when the cache are poisoned, all the packets have the right source
mac address and the switch is happy about it ;)

bye bye

    --==> ALoR <==---------------------- - - -

  ettercap project : http://ettercap.sourceforge.net
  e-mail: alor (at) users (dot) sourceforge (dot) net



Relevant Pages

  • RE: Exploit code for IP Smart Spoofing
    ... If there is a MAC violation, this is logged and the port is ... traffic of one other host on the switch. ... but there is no way to protect against ...
    (Bugtraq)
  • RE: mac duplication
    ... Another solution you could use depends on your switch. ... that allow you to do port mirroring. ... IP address map to MAC addresses via router tables. ... How do i set up mac duplication ...
    (Vuln-Dev)
  • Re: Ethernet switch flooding packets?
    ... course) so will have it's own MAC address. ... other VLANs there are are or how many hosts each has. ... was merely using the Ethernet switching terminology - if a switch ... doesn't know which individual port to push a frame out to, ...
    (comp.dcom.lans.ethernet)
  • Re: Network scanning
    ... that works with a radius server to auth mac address at port ... level before the switch will enable that port... ... new MAC and disable the port. ...
    (Security-Basics)
  • Re: Sniffing Internet Traffic
    ... >NIC's MAC to the new port so it can pass traffic. ... >for security because MITM ARP attacks are futile as the switch already ... >I don't know a whole lot about cable modems, but my guess is that, like ...
    (Security-Basics)