Re: Xen security / MAC hijack
Stefan de Konink <skinkie-qWit8jRvyhVmR6Xm/[email protected]> Mon, 26 Nov 2007 09:12:04 +0100
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi Grant, Grant Taylor schreef: > On 11/23/2007 7:47 AM, Stefan de Konink wrote: >> Xen host 1 has a hwaddr. >> >> Xen host 2 steels hwaddr of host 1. >> >> At that moment Xen host 1 is not reachable anymore. > > Ah, this is a fun scenario. ... and one that is rather difficult to > secure against. > >> Now I tried to prevent ARP packets in the forwarding chain that didn't >> match the mac that Xen reports as valid. But it seems the bridge get >> informed about this 'new interface' upon ifconfig eth0 up in an other >> way, or via an other route. > > Blocking ARPs is not enough. Equipment connected to the bridge will > learn the MAC address stolen by domain 2 other ways, i.e. GARP, sending > traffic, etc. > >> Is it possible to limit a source mac to a specific interface in a way >> that also ARP replies are blocked that indicate other macs? > > You need to intelligently forward traffic between your domains. You > will have to educate your bridge about what MAC addresses are allowed to > be where. On the Xen list someone suggested this: ebtables -t nat -A PREROUTING -i some-vif -s ! aa:00:00:6a:38:0c - --log-level debug --log-prefix 'SPOOF:' -j DROP Stefan -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFHSn/TYH1+F2Rqwn0RCq2yAJ4qam7pxXWaiA+MJfqL5VMmfN18zwCcDSGY r8Y0CGLiFNfrd4DYi0ajkxw= =WJAO -----END PGP SIGNATURE----- ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/