Vulnerability Development mailing list archives

Re: hijacking TCP connections on FreeBSD


From: Andreas Krennmair <a.krennmair () aon at>
Date: Thu, 11 Jul 2002 00:39:55 +0200

* jmiller <secadmin () subversive cc> [02-07-10 23:01]:
a man in the middle is not neccessary, you sniff the packets, spoof your ip
and or mac, then dos the other box you are spoofing. there is a *nix tool
that will do an arp flood, turning all switches into a hub, so you do not

It's a myth that "all switches" are vulnerable by such simple arp
flooding. "Good" switches shut down the port where arp flooding comes
from. Not even my el cheapo "Elsa" switch at home is vulnerable, I tried
it out, I wanted to present this attack to friends of mine.

ak
-- 
A one-character regular expression is a regular expression that
matches whatever the one-character regular expression matches.
  -- Sun regexp manpage

Attachment: _bin
Description:


Current thread: