|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2002-09-25, 18:34
|
cense 
Regular
|
|
|
|
OSPF confusion attacks
Just recently, i've been studying all about OSPF (Open Shortest Path First). Now, if I have to tell you what OSPF is then unfortunately I dont think you can help me.
Im thinking of a way to sniff the OSPF hello packets, reading the authentication information and reproducing it withing a forged OSPF packet. If I can do this, I can start telling OSPF routers that I am another router. I can then build packets advertising default routes and routes to places that dont exist. In the hacking world, this allows 2 things that I can see. 1) I can sniff connections by advertising myself as a default gateway router 2) I can overload router tables with routes to nowhere and bring them down by killing them when they perform the SPF calculations.
Now.. what I want to know if the possibility or probability of this actually working? I know I can sniff the hello packets but I dont know how im going to "crack" the authentication. If I can do that, the rest should simply be a matter of using Libnet to construct OSPF packets...
Anyone have ideas?
|
|
#2
 2002-09-25, 20:04
|
Jadedfool 
Regular
|
|
|
|
Re: OSPF confusion attacks
Authentication varies from site to site, so thats something you'll have to tackle when you implement it. As for imitating a router, while it would work if nobody was minding house, the second someone saw a new router on their network you'd be hosed. And I'm not exactly sure how the backup route system works, but assuming that you're not actually relaying the information to it's destination, then your route will stop being used.
basically, in order to make this work, you would have to create a router that actually had a faster route to the destination, which would require unprecedented physical access to the site. You would be better off just installing a packet sniffer next to the routers that already exist...
|
|
#3
 2002-09-26, 03:03
|
cense 
Regular
|
|
|
|
Re: OSPF confusion attacks
Thanks for replying. Im just playing with the idea right now, more to be developed.
|
|
#4
 2002-09-26, 03:06
|
cense 
Regular
|
|
|
|
Re: OSPF confusion attacks
Im fairly positive that if i send out a bunch of fake LSAs advertising routes that dont exists, and thus will never get used, that it is possible to have those routes stay in the victims routing tables. One of the problems I see here is that I would have to construct hundreds or thousands of fake routes in order to really affect a router. 2600 series would be overwhelmed fairly quickly but anything like a 7000 or better can handle thousands of routes without dying...
|
|
#5
 2002-09-26, 09:00
|
Jadedfool 
Regular
|
|
|
|
Re: OSPF confusion attacks
also you would have to consistently send the packets, because (once again relying on my dodgy memory) routers using OSPF have some sort of heartbeat between them...
|
|
#6
 2002-09-26, 10:40
|
|
|
Re: OSPF confusion attacks
and you should do this when they boot, because they know their neighbour.
|
|
#7
 2002-09-26, 14:28
|
cense 
Regular
|
|
|
|
Re: OSPF confusion attacks
quote: also you would have to consistently send the packets, because (once again relying on my dodgy memory) routers using OSPF have some sort of heartbeat between them...
Yes, very true. Hello timers are set to 10 seconds by defaults and from what i've heard, not many people change them, even so, you can determine the interval through sniffing. quote: and you should do this when they boot, because they know their neighbour.
An OSPF router can become neighbors with any other OSPF router at any time, not just duing boot. I don't believe this to be an issue. The only issue I see is adjencency. An OSPF router is only adjecent to the DR (Designated Router) or BDR (Backup Designated Router). To fully emulate this adjecency I would have to create code to emulate the hello packet exchange sequence that OSPF routers go through to become adjecent.... damn.
|
|
#8
 2002-09-26, 17:51
|
|
|
Re: OSPF confusion attacks
this depends on the type of network. On some the first neighbours are permanently.
|
|
#9
 2002-09-26, 19:59
|
Jadedfool 
Regular
|
|
|
|
Re: OSPF confusion attacks
good point, discovery protocol can be disabled...
|
|
#10
 2002-09-26, 21:56
|
cense 
Regular
|
|
|
|
Re: OSPF confusion attacks
Yeah... in a very secure environment I can see network techs turning off the discovery protocol, or alternatively, on very static networks. Any network in an evolving type state would be crippled with "discovery and recovery" turned off.
The point was that it really depends on the network, gotcha. Thanks guys, I appreciate the intellectuality of your responses.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|