Weaknesses in the Adelphia Powerlink Cable Modem Network
"0x90" <[email protected]>
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel |
|---|---|
| Organization | InvisibleNet |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Signing now for iip-dev only. Just so we know I wrote it ;) - --0x90-- I'd crawl over an acre of "Visual This++" and "Integrated Development That" to get to gcc, Emacs, and gdb. Thank you. - ----- Original Message ----- From: "0x90" <[email protected]> To: "0x90" <[email protected]> Sent: Monday, December 09, 2002 2:13 PM Subject: [iip-dev] Weaknesses in the Adelphia Powerlink Cable Modem Network > -------------------------------------------------------------------- > ------ > > InvisibleNet Security Advisory ISA 1-1 [email protected] > > http://www.invisiblenet.com > > December 9th, 2002 - report issued by 0x90 > > -------------------------------------------------------------------- > ------ > > Subject: Adelphia PowerLink Network vulnerable to Arp Poisoning > attacks and Promiscious sniffing. > > Vulnerability : Arp Poisoning and monitoring of Subnet(s) > > Problem-Type : remote > > OS Specific: N/A > > Problem Description: > > A certain set of subnets on Adelphia's Powerlink network are > treated as a HUB/SWITCH and therefore allow promiscious monitoring > of the subnet, and arp poisoning attacks as well. Upon finding this > flaw, it seems to only affect windows users dhcp requests, as for > *nix it hands off an entirely different subnet ip address that is > not vulnerable. This doesn't stop one from booting into *nix and > manually configuring their ip to be on the vulnerable subnet. To > review, with arp poisoning, one can do a tremendous amount of > malicious activity on a subnet, from DoS'ing the network, to > hijacking DNS servers, and even attacking/cracking SSL/SSH/VPN > negotiations. Promiscious mode, one can passively monitor all > traffic on the subnet, obtaining private information, including > logins/passwords, and private email. > > Vulnerable Subnets: > > Known Subnets > > -------------------------------------------------------------------- > -------- --------------------------- > > 24.52.209.x (others probably are, just not tested) > > > > Solution: > > The proper solution is varying on how the cable networks topology > is handled, and arp poisoning, as we know is not a completely > solvable issue without a physical/virutal separation of Layer 3 > from Layer 2 in the OSI Model. For promiscious mode, rather simple, > don't have the network in HUB mode. > > Patch: > > N/A. > > Disclaimer: > > This information is being withheld as a public advisory and will > not be released until 30 days from this date in order to give time > for vendor response. This does not exclude any Research & > Development mailing lists that are owned by InvisibleNet, and/or > any researchers or developers that are affiliated with > InvisibleNet. > > InvisibleNet is not responsible for the misuse of any of the > information we provide on this website and/or through our security > advisories. Our advisories are a service to our customers intended > to promote secure installation and use of InvisibleNet products. > > > -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com> iQA/AwUBPfUXmDep2+UpsNFNEQJhHgCg3yEXM3COShx8DBQdOEw6YkoO7/MAoJTK Y9sdl6QtwVy0gU4usPv3SNMf =oiFR -----END PGP SIGNATURE-----