Re: Xen security / MAC hijack

Stefan de Konink <skinkie-qWit8jRvyhVmR6Xm/[email protected]> Mon, 26 Nov 2007 09:12:04 +0100
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi Grant,

Grant Taylor schreef:
> On 11/23/2007 7:47 AM, Stefan de Konink wrote:
>> Xen host 1 has a hwaddr.
>>
>> Xen host 2 steels hwaddr of host 1.
>>
>> At that moment Xen host 1 is not reachable anymore.
> 
> Ah, this is a fun scenario.  ... and one that is rather difficult to 
> secure against.
> 
>> Now I tried to prevent ARP packets in the forwarding chain that didn't
>> match the mac that Xen reports as valid. But it seems the bridge get
>> informed about this 'new interface' upon ifconfig eth0 up in an other
>> way, or via an other route.
> 
> Blocking ARPs is not enough.  Equipment connected to the bridge will 
> learn the MAC address stolen by domain 2 other ways, i.e. GARP, sending 
> traffic, etc.
> 
>> Is it possible to limit a source mac to a specific interface in a way
>> that also ARP replies are blocked that indicate other macs?
> 
> You need to intelligently forward traffic between your domains.  You 
> will have to educate your bridge about what MAC addresses are allowed to 
> be where.


On the Xen list someone suggested this:

ebtables -t nat -A PREROUTING -i some-vif -s ! aa:00:00:6a:38:0c
- --log-level debug --log-prefix 'SPOOF:' -j DROP


Stefan
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHSn/TYH1+F2Rqwn0RCq2yAJ4qam7pxXWaiA+MJfqL5VMmfN18zwCcDSGY
r8Y0CGLiFNfrd4DYi0ajkxw=
=WJAO
-----END PGP SIGNATURE-----

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/