Let the Games Begin

Unfortunately, you are likely to come across LAN hackers that are intimately familiar with STP's inner workings. They also know that little or no attention is paid to STP security. They realize how gullible—for lack of a better term—the protocol actually is. STP attacks moved from the theoretical field to reality fairly recently. Black Hat Europe 2005 proposed a session that discussed various ways to exploit STP3. Packet-building libraries, such as libnet4, have been shipping C-source code to help craft homemade BPDUs for some time now, but putting together an attack tool required some programming skills—a fact that probably deterred most script kiddies. It was only a matter of time before someone built a frontend to a libnet-based LAN protocol's packet-building machine. Probably the most successful result of that effort is a tool called Yersinia. Example 3-1 shows Yersinia's manual page.

Example 3-1 Yersinia Manual Page YERSINIA(8)

NAME

Yersinia - A Framework for layer 2 attacks SYNOPSIS

yersinia [-hVID] [-1 logfile] [-c conffile] protocol [-M] [protoco1_options]

DESCRIPTION

yersinia is a framework for performing layer 2 attacks. The following protocols have been implemented in Yersinia current version: Spanning Tree Protocol (STP), Virtual Trunking Protocol (VTP), Hot Standby Router Protocol (HSRP), Dynamic Trunking Protocol (DTP), IEEE 802.1Q, Cisco Discovery Protocol continues

Example 3-1 Yersinia Manual Page (Continued)

(CDP) and finally, the Dynamic Host Configuration Protocol (DHCP).

Some of the attacks implemented will cause a DoS in a network, other will help to perform any other more advanced attack, or both. In addition, some of them will be first released to the public since there isn't any public implementation.

The tool basically covers all the most common LAN protocols deployed in today's networks: STP, VLAN Trunk Protocol (VTP), Hot Standby Router Protocol(HSRP), Dynamic Trunking Protocol (DTP), Cisco Discovery Protocol (CDP), DHCP—they are all in there. Even worse, it comes with a GUI! According to Yersinia's home page,5 it proposes these STP attacks:

• Sending RAW Configuration BPDU

• Sending RAW TCN BPDU

• Denial of Service (DoS) sending RAW Configuration BPDU

• DoS Sending RAW TCN BPDU

• Claiming Root Role

• Claiming Other Role

• Claiming Root Role Dual-Home (MITM)

Basically, Yersinia has everything that anyone interested in messing around with STP would ever need. The GUI is based on the ncurses library (for character-cell terminals, such as VT100). Figure 3-5 shows Yersinia's protocols.

Yersinia continuously listens for STP BPDUs and provides instant decoded information, including current root bridge and timers it is propagating—all this for 802.1D, 802.1w, and Cisco BPDUs. The following sections review the major STP attacks and offer appropriate countermeasures.

Figure 3-5 Yersinia's Protocols

Figure 3-5 Yersinia's Protocols

Continue reading here: BPDU Filtering

Was this article helpful?

0 0