Security Basics mailing list archives

RE: how secure is a vlan


From: "Shepler, Eric W. [Contractor]" <sheplere () spawar navy mil>
Date: Wed, 7 Jan 2004 12:42:34 -0500

Short answer. 

Is this technology as secure as physical net ?  No.
Is there a way to break out of this virtual lan into another part of the
network ?  Yes.


Try this as a starting point.
VLAN transversal typically occurs via error in network hardware
configuration, or vulnerability in network operating systems software.

See the links below for information:

http://www.packetfactory.net/papers/VLAN-hopping/stake_wp.pdf

http://www.cisco.com/warp/public/cc/pd/si/casi/ca6000/prodlit/vlnwp_wp.htm

http://www.cisco.com/ca/events/pdfs/L2-security-Bootcamp-final.pdf

Also, references and resources used to build these documents are another
place for more information.

-----Original Message-----
From: tigerblue () puzzleapuma de [mailto:tigerblue () puzzleapuma de]
Sent: Wednesday, January 07, 2004 5:02 AM
To: security-basics () securityfocus com
Subject: how secure is a vlan


Hello Outthere,

I´m planing a reorganisation of our company network. I´m thinking about
a vlan to secure a part of the net. Is this technology as secure as
physical net ? Is there a way to break out of this virtual lan into
another part of the network ?

Best Regards

tigerblue

--------------------------------------------------------------------------
-
Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any
course! All of our class sizes are guaranteed to be 10 students or less.
We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion
Prevention,
and many other technical hands on courses.
Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off
any course!
--------------------------------------------------------------------------
--

---------------------------------------------------------------------------
Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any
course! All of our class sizes are guaranteed to be 10 students or less.
We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention,
and many other technical hands on courses.
Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off
any course!
----------------------------------------------------------------------------


Current thread: