Re: Dual-Homed/Triple-Subnet Bridge Challenge

Grant Taylor <[email protected]> Tue, 12 Feb 2008 16:42:12 -0600
Newsgroups gmane.linux.network.bridge.ebtables.user
Organization Riverview Technologies Inc.
Message-ID <[email protected]>
On 02/12/08 16:15, Carl-Daniel Hailfinger wrote:
> Yes, but unless the client is connected to two different switches, I 
> don't see a way to abuse STP to trick the switch to send all traffic 
> to it.

I think I could come up with ways to abuse STP (making a royal mess of 
the STP topology), but all of which are beyond what the OP was wanting 
to do.  I mainly brought STP up as optional reading down the road.

> And exactly this is how you can force a switch to send all traffic to 
> the client. Have the client send a continuous stream of packets with 
> a spoofed source MAC of the computer you want to eavesdrop on. The 
> switch is tricked into learning that the most recent location of the 
> victim is the sniffing client. No need to mess with ARP. However, 
> this usually causes the switch to not send packets to the victim 
> anymore, so it may not be exactly what you want.

*nod*  This MAC Spoofing will get you the packets, but it will tend to 
leave the spoofed real client dead in the water, and thus break connections.

> The other way to get all traffic to a switch relayed to the sniffing 
> client relies on downgrading the switch to a hub. Switches only have 
> a limited number of MAC addresses they can store in their forwarding 
> table. If you fill the table with fake entries, the switch doesn't 
> know where to send a specific packet and sends it everywhere. Thus, 
> it has effectively become a hub.

Now you are starting to do some things that are easily detectable and 
will tend to set off alarms.

> To prevent attacks of that type, you can enable port security on the 
> switch or use more advanced features.
> 
> On the other hand, if you are the network admin, you can tell a 
> switch to copy all traffic it receives to another port with a feature 
> called "port mirroring" or "roving analysis".

These are all viable things that more than casual network admins should 
at least be aware of in case they ever need to do them.  They are also 
beyond what the OP was wanting to do.



Grant. . . .

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/