Penetration Testing mailing list archives

Re: VLAN hopping - demonstration


From: "David M. Zendzian" <dmz () dmzs com>
Date: Tue, 17 Oct 2006 19:52:39 -0400

Have you thought about just plugging in a linux machine (or cdbootable) and having it take care of the vlan stuff for you (join all VLANS from one linux box).

dubaisans dubai wrote:
How do you demonstrate VLAN hopping?. I am trying to show this to a
customer who has mutliple DMZ segments configured as Layer2 VLANs on a
Cisco 6500 switch.  There is NO trunk port on this switch but DTP is
turned on on all ports.

Is it enough to cascade another L2 switch on an access port [ say VLAN
100] of the 6509, connect a desktop on this second switch and send a
packet with different VLAN ID [say VLAN 200] on the 6509.

Am I on the right track?

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: