|
|||||||||||
|
Windows 2000 Static arp not static
From: Tim Habex <tim.habex(at)eenderwat.be>
Date: Wed Feb 12 2003 - 18:53:44 EST I am quite new to this. I posted this on bugtraq first, but David Ahmad asked to post it in FOCUS-MS and vuln-dev. So here I go :o)
This is the setup :
(The linux distro's doesn't really matter)
When using ethercap on the network from de Debian machine, I was able to see and control all trafic. (nothing new right?) Ethercap is doing this by making the network believe everything should be sent to the MAC-address of the ethercap machine which in my case was the Debian machine. To prevent this behaviour, I setup static routes both on the gateway and the Windows machine. Yet I didn't get the result I was expecting. I was still able to see packets on the Debian machine, yet I was no longer able to control the packets. Meaning Windows 2000 desktops (and servers?) can always be sniffed even when using a switch. On top of that, your network is probably vulnerable to the man-in-the-middle attacks if you're relying on MS-technology only. I don't know if they are still vulnerable to a man-in-the-middle attack if you're using eg. a Linux router with static routes. My "hacking" knowlege is quite limited. But I can imagine there are people who know how to gain from this "feature". If this is a known problem, why hasn't this been fixed. If unknown ... is
Microsoft reading this? ;o)
Hoping this can be usefull Tim Received on Wed Feb 12 19:05:33 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:26 EDT |
||||||||||
|
|||||||||||