Skip to content

Comment on The Little White Box That Can Hack Your Networkparent

Comments

For every local LAN attack there are mitigation techniques. Cisco Switches have great features like DHCP Snooping and Dynamic ARP Inspection (DAI) to eliminate rogue DHCP servers and ARP spoofing.

Further yet, with "switch-port security" you can lock down mac addresses per port. With port security and proper device segregation if you spoofed a phones mac address and plugged in to that port the switch would still put you in to only the voice vlan not the data lan. It's not perfect but there are a lot of things you can do to secure a local LAN.

Unfortunately, most businesses must not even do the bare minimum if all they have to do is plug in a single PwnPlug without any attack vectors implemented like mac spoofing.

Yep. My University implemented switch-port security before I arrived in 2001. Managed switches, central MAC register, you were placed on the VLAN your MAC said you belonged to.

If your MAC appeared twice, you'd be locked out of the network and need to go and do some explaining (!). If your MAC moved around too much, ditto. If you had more than one ARP entry for your port, ditto.

While this makes some sense, what happens if you plug your laptop into your roommates port? My university had a policy of disallowing students on the internal network - there was wifi and some special network ports with red cables for students. A classmate had a virus and was tracked down and yelled at in class because he was also plugged into the internal network...

The FE College I teach at (not residential) has a 'guest' wifi for any device you want. Just internet access, no https let alone any other protocol. The teenagers mainly use it with their Blackberry phones to get on BBM :-)

Full authentication is only for College owned devices, not sure how they are managing that.

No SSL? That's a terrible way to run a network. SSL is very important when using open WiFi.

No https because the College don't want students buying things over the College connection. Also stops me using Ubuntu launchpad in breaks

It also emphasizes though that you shouldn't be doing anything long term or mission critical, but just for checking that one little thing...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.