Re: Security Appliance With 12 Network Segments
- From: Leythos <spam999free@xxxxxxxxxx>
- Date: Fri, 15 Apr 2011 14:14:47 -0400
In article <io9t2u$b0g$1@xxxxxxxxxxxxxxxxx>, news2009@xxxxxxxxx says...
On Fri, 15 Apr 2011 12:42:55 -0400, me again wrote:
What if I setup my own address including the mac address?
DHCP can limit itself to "MAC" numbers it has been given. "MAC" numbers
are not really addresses at all, just ID numbers.
I know, thats why I'm interested how he might prevent an attack like that.
For it to work you have to program your NIC with a MAC on the approved
list. Sure, you can make them up, but if they don't match what's been
approved it won't do you much good.
The DHCP limit is a fair security measure, except that various device
can "clone" a "MAC" number, thus making this feature pretty useless.
Programming in the MAC addresses is also an administrative nightmare
OK, you can record those adresses easily that shouldn't be the issue, I
just wonder if coworker a is on vacation and I can't access his computer
(lets assume I would need a token), what happens if I connect a laptop to
the network and use his MAC.
If you can't access his computer then you won't know what his MAC is.
It's more a theoretical idea then a practical since I would have to
try every possible combination and wait if the dhcpd sends me an
address.
Look around google, there are a few ways to implement it that provide
basic blocking to unknown devices, it's not a nighmare at all, it's
actually just a few minutes work.
--
You can't trust your best friends, your five senses, only the little
voice inside you that most civilians don't even hear -- Listen to that.
Trust yourself.
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.
- Follow-Ups:
- Re: Security Appliance With 12 Network Segments
- From: Burkhard Ott
- Re: Security Appliance With 12 Network Segments
- References:
- Re: Security Appliance With 12 Network Segments
- From: me again
- Re: Security Appliance With 12 Network Segments
- From: W
- Re: Security Appliance With 12 Network Segments
- From: Burkhard Ott
- Re: Security Appliance With 12 Network Segments
- From: Leythos
- Re: Security Appliance With 12 Network Segments
- From: Burkhard Ott
- Re: Security Appliance With 12 Network Segments
- From: Leythos
- Re: Security Appliance With 12 Network Segments
- From: Burkhard Ott
- Re: Security Appliance With 12 Network Segments
- From: Leythos
- Re: Security Appliance With 12 Network Segments
- From: Burkhard Ott
- Re: Security Appliance With 12 Network Segments
- From: me again
- Re: Security Appliance With 12 Network Segments
- From: Burkhard Ott
- Re: Security Appliance With 12 Network Segments
- Prev by Date: Re: Security Appliance With 12 Network Segments
- Next by Date: Re: Security Appliance With 12 Network Segments
- Previous by thread: Re: Security Appliance With 12 Network Segments
- Next by thread: Re: Security Appliance With 12 Network Segments
- Index(es):
Relevant Pages
|