Weaknesses in the Adelphia Powerlink Cable Modem Network

"0x90" <[email protected]>
Newsgroups gmane.comp.security.invisiblenet.iip.devel
Organization InvisibleNet
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Signing now for iip-dev only. Just so we know I wrote it ;)
- --0x90--
I'd crawl over an acre of "Visual This++" and "Integrated Development
That" to get to gcc, Emacs, and gdb.  Thank you.

- ----- Original Message ----- 
From: "0x90" <[email protected]>
To: "0x90" <[email protected]>
Sent: Monday, December 09, 2002 2:13 PM
Subject: [iip-dev] Weaknesses in the Adelphia Powerlink Cable Modem
Network


> --------------------------------------------------------------------
> ------  
> 
> InvisibleNet Security Advisory ISA 1-1 [email protected]
> 
> http://www.invisiblenet.com
> 
> December 9th, 2002 - report issued by 0x90
> 
> --------------------------------------------------------------------
> ------  
> 
> Subject: Adelphia PowerLink Network vulnerable to Arp Poisoning
> attacks and Promiscious sniffing.
> 
> Vulnerability : Arp Poisoning and monitoring of Subnet(s)
> 
> Problem-Type : remote
> 
> OS Specific: N/A
> 
> Problem Description:
> 
> A certain set of subnets on Adelphia's Powerlink network are
> treated as a HUB/SWITCH and therefore allow promiscious monitoring
> of the subnet, and arp poisoning attacks as well. Upon finding this
> flaw, it seems to only affect windows users dhcp requests, as for
> *nix it hands off an entirely different subnet ip address that is
> not vulnerable. This doesn't stop one from booting into *nix and
> manually configuring their ip to be on the vulnerable subnet. To
> review, with arp poisoning, one can do a tremendous amount of
> malicious activity on a subnet, from DoS'ing the network, to
> hijacking DNS servers, and even attacking/cracking SSL/SSH/VPN
> negotiations. Promiscious mode, one can passively monitor all
> traffic on the subnet, obtaining private information, including
> logins/passwords, and private email.
> 
> Vulnerable Subnets:
> 
>    Known Subnets
> 
> --------------------------------------------------------------------
> -------- ---------------------------
> 
> 24.52.209.x (others probably are, just not tested)
> 
> 
> 
> Solution:
> 
> The proper solution is varying on how the cable networks topology
> is handled, and arp poisoning, as we know is not a completely
> solvable issue without a physical/virutal separation of Layer 3
> from Layer 2 in the OSI Model. For promiscious mode, rather simple,
> don't have the network in HUB mode.
> 
> Patch:
> 
> N/A.
> 
> Disclaimer:
> 
> This information is being withheld as a public advisory and will
> not be released until 30 days from this date in order to give time
> for vendor response. This does not exclude any Research &
> Development mailing lists that are owned by InvisibleNet, and/or
> any researchers or developers that are affiliated with
> InvisibleNet.
> 
> InvisibleNet is not responsible for the misuse of any of the
> information we provide on this website and/or through our security
> advisories. Our advisories are a service to our customers intended
> to promote secure installation and use of InvisibleNet products.
> 
> 
> 

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBPfUXmDep2+UpsNFNEQJhHgCg3yEXM3COShx8DBQdOEw6YkoO7/MAoJTK
Y9sdl6QtwVy0gU4usPv3SNMf
=oiFR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.