About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-09-25, 18:34
cense cense is offline
Regular
 
Default OSPF confusion attacks

Just recently, i've been studying all about OSPF (Open Shortest Path First). Now, if I have to tell you what OSPF is then unfortunately I dont think you can help me.

Im thinking of a way to sniff the OSPF hello packets, reading the authentication information and reproducing it withing a forged OSPF packet. If I can do this, I can start telling OSPF routers that I am another router. I can then build packets advertising default routes and routes to places that dont exist. In the hacking world, this allows 2 things that I can see. 1) I can sniff connections by advertising myself as a default gateway router 2) I can overload router tables with routes to nowhere and bring them down by killing them when they perform the SPF calculations.

Now.. what I want to know if the possibility or probability of this actually working? I know I can sniff the hello packets but I dont know how im going to "crack" the authentication. If I can do that, the rest should simply be a matter of using Libnet to construct OSPF packets...

Anyone have ideas?
 #2 
Old 2002-09-25, 20:04
Jadedfool Jadedfool is offline
Regular
 
Default Re: OSPF confusion attacks

Authentication varies from site to site, so thats something you'll have to tackle when you implement it. As for imitating a router, while it would work if nobody was minding house, the second someone saw a new router on their network you'd be hosed. And I'm not exactly sure how the backup route system works, but assuming that you're not actually relaying the information to it's destination, then your route will stop being used.

basically, in order to make this work, you would have to create a router that actually had a faster route to the destination, which would require unprecedented physical access to the site. You would be better off just installing a packet sniffer next to the routers that already exist...

 #3 
Old 2002-09-26, 03:03
cense cense is offline
Regular
 
Default Re: OSPF confusion attacks

Thanks for replying. Im just playing with the idea right now, more to be developed.
 #4 
Old 2002-09-26, 03:06
cense cense is offline
Regular
 
Default Re: OSPF confusion attacks

Im fairly positive that if i send out a bunch of fake LSAs advertising routes that dont exists, and thus will never get used, that it is possible to have those routes stay in the victims routing tables. One of the problems I see here is that I would have to construct hundreds or thousands of fake routes in order to really affect a router. 2600 series would be overwhelmed fairly quickly but anything like a 7000 or better can handle thousands of routes without dying...
 #5 
Old 2002-09-26, 09:00
Jadedfool Jadedfool is offline
Regular
 
Default Re: OSPF confusion attacks

also you would have to consistently send the packets, because (once again relying on my dodgy memory) routers using OSPF have some sort of heartbeat between them...
 #6 
Old 2002-09-26, 10:40
Moderator
 
Default Re: OSPF confusion attacks

and you should do this when they boot, because they know their neighbour.
 #7 
Old 2002-09-26, 14:28
cense cense is offline
Regular
 
Default Re: OSPF confusion attacks

quote:
also you would have to consistently send the packets, because (once again relying on my dodgy memory) routers using OSPF have some sort of heartbeat between them...


Yes, very true. Hello timers are set to 10 seconds by defaults and from what i've heard, not many people change them, even so, you can determine the interval through sniffing.

quote:
and you should do this when they boot, because they know their neighbour.


An OSPF router can become neighbors with any other OSPF router at any time, not just duing boot. I don't believe this to be an issue. The only issue I see is adjencency. An OSPF router is only adjecent to the DR (Designated Router) or BDR (Backup Designated Router). To fully emulate this adjecency I would have to create code to emulate the hello packet exchange sequence that OSPF routers go through to become adjecent.... damn.
 #8 
Old 2002-09-26, 17:51
Moderator
 
Default Re: OSPF confusion attacks

this depends on the type of network. On some the first neighbours are permanently.
 #9 
Old 2002-09-26, 19:59
Jadedfool Jadedfool is offline
Regular
 
Default Re: OSPF confusion attacks

good point, discovery protocol can be disabled...
 #10 
Old 2002-09-26, 21:56
cense cense is offline
Regular
 
Default Re: OSPF confusion attacks

Yeah... in a very secure environment I can see network techs turning off the discovery protocol, or alternatively, on very static networks. Any network in an evolving type state would be crippled with "discovery and recovery" turned off.

The point was that it really depends on the network, gotcha. Thanks guys, I appreciate the intellectuality of your responses.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics