Re: Xen security / MAC hijack

Grant Taylor <[email protected]> Sun, 25 Nov 2007 23:28:54 -0600
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
On 11/23/2007 7:47 AM, Stefan de Konink wrote:
> Xen host 1 has a hwaddr.
> 
> Xen host 2 steels hwaddr of host 1.
> 
> At that moment Xen host 1 is not reachable anymore.

Ah, this is a fun scenario.  ... and one that is rather difficult to 
secure against.

> Now I tried to prevent ARP packets in the forwarding chain that didn't
> match the mac that Xen reports as valid. But it seems the bridge get
> informed about this 'new interface' upon ifconfig eth0 up in an other
> way, or via an other route.

Blocking ARPs is not enough.  Equipment connected to the bridge will 
learn the MAC address stolen by domain 2 other ways, i.e. GARP, sending 
traffic, etc.

> Is it possible to limit a source mac to a specific interface in a way
> that also ARP replies are blocked that indicate other macs?

You need to intelligently forward traffic between your domains.  You 
will have to educate your bridge about what MAC addresses are allowed to 
be where.



Grant. . . .

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/