Weaknesses in the Adelphia Powerlink Cable Modem Network
"0x90" <[email protected]>
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel,gmane.spam.detected |
|---|---|
| Organization | InvisibleNet |
| Message-ID | <[email protected]> |
-------------------------------------------------------------------------- InvisibleNet Security Advisory ISA 1-1 [email protected] http://www.invisiblenet.com December 9th, 2002 - report issued by 0x90 -------------------------------------------------------------------------- Subject: Adelphia PowerLink Network vulnerable to Arp Poisoning attacks and Promiscious sniffing. Vulnerability : Arp Poisoning and monitoring of Subnet(s) Problem-Type : remote OS Specific: N/A Problem Description: A certain set of subnets on Adelphia's Powerlink network are treated as a HUB/SWITCH and therefore allow promiscious monitoring of the subnet, and arp poisoning attacks as well. Upon finding this flaw, it seems to only affect windows users dhcp requests, as for *nix it hands off an entirely different subnet ip address that is not vulnerable. This doesn't stop one from booting into *nix and manually configuring their ip to be on the vulnerable subnet. To review, with arp poisoning, one can do a tremendous amount of malicious activity on a subnet, from DoS'ing the network, to hijacking DNS servers, and even attacking/cracking SSL/SSH/VPN negotiations. Promiscious mode, one can passively monitor all traffic on the subnet, obtaining private information, including logins/passwords, and private email. Vulnerable Subnets: Known Subnets ---------------------------------------------------------------------------- --------------------------- 24.52.209.x (others probably are, just not tested) Solution: The proper solution is varying on how the cable networks topology is handled, and arp poisoning, as we know is not a completely solvable issue without a physical/virutal separation of Layer 3 from Layer 2 in the OSI Model. For promiscious mode, rather simple, don't have the network in HUB mode. Patch: N/A. Disclaimer: This information is being withheld as a public advisory and will not be released until 30 days from this date in order to give time for vendor response. This does not exclude any Research & Development mailing lists that are owned by InvisibleNet, and/or any researchers or developers that are affiliated with InvisibleNet. InvisibleNet is not responsible for the misuse of any of the information we provide on this website and/or through our security advisories. Our advisories are a service to our customers intended to promote secure installation and use of InvisibleNet products.