About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-10-25, 02:30
cense cense is offline
Regular
 
Default drying up a DHCP pool

Some thoughts... How would be possible to "dry" up a dhcp pool? Im just speculating here, if you have anything to add, please do.

To deny NEW clients access: To remove the availability of any *more* dhcp clients gaining access to a network, one would have to make a DHCP server assign every non-leased address in its pool. This can theoretically be done by spoofing DHCPDiscover/Request packets and fooling the DHCP server into assigning an IP to a spoofed MAC sent along with the DHCPDiscover/Request packets. The switch would also have to be "told" that off of your port, exists the spoofed MAC addresses, in essense, poisoning the ARP cache as skalez was asking about. So... by poisoning the ARP cache, and sending false DHCPDiscover/Request packets, could one get a DHCP server to assign away every address in it's pool?

If the client machine propagating this attack gathered all the DHCPOffer and DHCPAck packets, it could maintain its own listing of false MAC-to-IP mappings along with lease times so that at 50% of the lease time, the lease could be extended by another DHCPRequest packet... this would prolong the DoS against the DHCP server.

Now the issue of "stealing" MAC-to-IP mappings that are already assigned/lease out... here im kinda lost, and where I would like some input. I think one would go about it the same way as above, but im not quite sure... hmmm.

Yes, this is just me blabering about bullshit. Help if you can
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics