Penetration Testing mailing list archives

Re: [PEN-TEST] Spoofing switched networks


From: Ryan Russell <ryan () SECURITYFOCUS COM>
Date: Tue, 6 Feb 2001 17:19:46 -0700

On Tue, 6 Feb 2001, Jason Brvenik wrote:

As for switching, I'm fully aware that it's not a security mechanism
that
cannot be defeated easily. However that VLANs have no security impact is
news to me. Since VLANS are defined on physical switch port basis, how
could
they be used to receive or send traffic on other VLANs?

Because VLAN ports are under the control of the same software that switch
ports are.  VLAN boundaries fall for the same classes of attack that MAC
address filtering does.  There are even more features to attack for a
typical VLAN switch.

                                Ryan


Current thread: