Table 315 Rogue Devices

Attack name

Rogue devices

Class/subclass

Spoof

Sample implementations

Any legitimate networking device; popular choices include WLAN AP, DHCP server, router, host

Prerequisites

Physical access

Pertinent vulnerability

Usage or physical security controls

Typical use

Offer services to a user community; stealing data as their requests are passed through to the legitimate network

Attack result

Disclosure and corruption of information

Likely follow-up attacks

Read and manipulate

OSI layers

All

Detection

Varies by rogue device

Protection

Varies by rogue device

Detection difficulty

3

Ease of use

2

Frequency

2

Impact

5

Overall rating

33

Until now in the discussion, the spoofing attack class has exclusively contained software-based attacks in which attackers attempt to convince network resources or clients that they are something they are not. In the rogue device attack, however, attackers introduce a rogue device into the network, hoping to convince other devices and users that the device is valid. The "Everything is a weapon" axiom from Chapter 1 discusses the rogue AP attack in some detail. It is also easy to reclassify the DHCP attack mentioned in the same section as a rogue device rather than a compromised one. If attackers simply introduced a new DHCP server into the network, they would be able to accomplish much the same thing.

A host could also be introduced as a rogue device. The DC Phone Home project shows how an attacker can introduce a PC, Sega Dreamcast, or Compaq iPAQ into a network to run remote attacks. The system is introduced into the network, where it attempts to determine the IP addressing and the presence of a HTTP proxy server and then creates a tunneled connection back out to the attacker. This gives a remote attacker a local presence from which to launch attacks. From here, local attacks such as ARP redirection or MAC flooding are possible. For more information about the DC Phone Home project, see the following URL: http://www.dcphonehome.com/.

The use of rogue devices can be a devastating attack, but such attacks generally require the attacker to have physical access to the target network. The detection of a rogue device can be difficult or easy, depending on how the network is managed and the specific type of rogue device. Techniques for rogue device detection and mitigation are covered in Chapter 5, "Device Hardening."

Continue reading here: MAC Flooding

Was this article helpful?

0 0