MAC Flooding
Table 3-16 shows the summary information for the MAC flooding attack.
|
Attack name |
MAC flooding |
|
Class/subclass |
Flood |
|
Sample implementations |
macof |
|
Prerequisites |
Local LAN access |
|
Pertinent vulnerability |
Policy |
|
Typical use |
Fill a switch's CAM table and then sniff the legitimate traffic that floods as a result |
|
Attack result |
Disclosure of information |
|
Likely follow-up attack |
Read and manipulate |
|
OSI layers |
2 |
|
Detection |
Switch monitoring (CAM table size) |
|
Protection |
Port security |
|
Detection difficulty |
3 |
|
Ease of use |
5 |
|
Frequency |
1 |
|
Impact |
3 |
|
Overall rating |
28 |
MAC flooding refers to sending packets with spoofed source and destination MAC addresses from the attacker's system to the Ethernet network. The CAM table, which keeps track of MAC address locations on a switch, has a limited size. If that table is filled, frames destined to MAC addresses without a CAM entry are flooded on the local VLAN to ensure delivery to the correct host. This allows the attacker to sniff those frames just as if the attacker were on a shared, rather than switched, Ethernet segment. The "MAC Flooding Considerations" section of Chapter 6 goes into great detail on CAM tables, the MAC flooding attack, and using port security to block the attack.
Continue reading here: Figure 311 Smurf Attack
Was this article helpful?