Weaknesses in the Adelphia Powerlink Cable Modem Network

"0x90" <[email protected]>
Newsgroups gmane.comp.security.invisiblenet.iip.devel,gmane.spam.detected
Organization InvisibleNet
Message-ID <[email protected]>
--------------------------------------------------------------------------

InvisibleNet Security Advisory ISA 1-1 [email protected]

http://www.invisiblenet.com

December 9th, 2002 - report issued by 0x90

--------------------------------------------------------------------------

Subject: Adelphia PowerLink Network vulnerable to Arp Poisoning attacks and
Promiscious sniffing.

Vulnerability : Arp Poisoning and monitoring of Subnet(s)

Problem-Type : remote

OS Specific: N/A

Problem Description:

A certain set of subnets on Adelphia's Powerlink network are treated as a
HUB/SWITCH and therefore allow promiscious monitoring of the subnet, and arp
poisoning attacks as well. Upon finding this flaw, it seems to only affect
windows users dhcp requests, as for *nix it hands off an entirely different
subnet ip address that is not vulnerable. This doesn't stop one from booting
into *nix and manually configuring their ip to be on the vulnerable subnet.
To review, with arp poisoning, one can do a tremendous amount of malicious
activity on a subnet, from DoS'ing the network, to hijacking DNS servers,
and even attacking/cracking SSL/SSH/VPN negotiations. Promiscious mode, one
can passively monitor all traffic on the subnet, obtaining private
information, including logins/passwords, and private email.

Vulnerable Subnets:

   Known Subnets

----------------------------------------------------------------------------
---------------------------

24.52.209.x (others probably are, just not tested)



Solution:

The proper solution is varying on how the cable networks topology is
handled, and arp poisoning, as we know is not a completely solvable issue
without a physical/virutal separation of Layer 3 from Layer 2 in the OSI
Model. For promiscious mode, rather simple, don't have the network in HUB
mode.

Patch:

N/A.

Disclaimer:

This information is being withheld as a public advisory and will not be
released until 30 days from this date in order to give time for vendor
response. This does not exclude any Research & Development mailing lists
that are owned by InvisibleNet, and/or any researchers or developers that
are affiliated with InvisibleNet.

InvisibleNet is not responsible for the misuse of any of the information we
provide on this website and/or through our security advisories. Our
advisories are a service to our customers intended to promote secure
installation and use of InvisibleNet products.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.