Vulnerability Development mailing list archives

More on ARP cache poisoning


From: shawn.a.clifford () LMCO COM (Clifford, Shawn A)
Date: Tue, 1 Feb 2000 16:35:35 -0500


I tried to see if it would be possible to poison the ARP cache of my machine
(Solaris 2.6) so that it contained an Ether address of a local machine, but
the IP address of a machine outside my network (prep.ai.mit.edu, for
example).

I didn't work.  Not with the 'poink' program nor with 'arp -s <host>
<ether>'.  The ARP cache in Solaris anyway is smart enough to not take
entries for remote networks.  Maybe someone else can try on Linux and other
platforms.  I will try under HP-sUX when I get a chance.

So, this pretty much makes moot hijacking the SETI download, etc.  You can
ony use the ARP poison to redirect connections _within_ or LAN.

If anybody finds a way around this, please post the solution.

-- Shawn


Current thread: