
Layer 2 Netzwerk-Angriffsframework zur Ausnutzung von STP- und CDP-Protokollen, das DoS-, Root-Rollen-Hijacking- und Speichererschöpfungsangriffe auf Cisco-Switches ermöglicht.
Lass uns ein paar conf BPDUs senden, die vorgeben, Root zu sein!!! Durch das kontinuierliche Senden von conf BPDUs mit Root-Pfadkosten 0, einer zufällig generierten Bridge-ID (und daher derselben Root-ID) sowie einigen Standardwerten für andere Felder versuchen wir, die Switches in unserer Nähe zu stören und einen DoS zu verursachen, wenn sie versuchen, ihre STP-Engines zu parsen und neu zu berechnen.
Source MAC: zufällig generiert.
Destination MAC: 01:80:c2:00:00:00
Bridge ID: 8000:source_mac
Root ID: 8000:source_mac
Hello time: 2
Forward delay: 15
Max age: 20
Root pathcost: 0
<output from the cisco log>
01:20:26: STP: VLAN0001 heard root 32768-d1bf.6d60.097b on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-9ac6.0f72.7118 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-85a3.3662.43dc on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-3d84.bc1c.918e on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-b2e2.1a12.dbb4 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-4ba6.2d45.5844 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-deb0.4f14.7288 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-4879.8036.0e24 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-2776.e340.9222 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-299e.de76.c07d on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-d38b.bc5b.e90d on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-78ee.0205.afdb on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-b32b.e969.81b1 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-b16b.c428.88a3 on Fa0/8
01:20:26: STP: VLAN0001 heard root 32768-dd01.1436.9044 on Fa0/8
</output>
Dieser Angriff sendet kontinuierlich tcn BPDUs, wodurch der Root-Switch gezwungen wird, conf BPDUs zu senden, die die Änderung bestätigen. Darüber hinaus sendet der Root-Switch Topologieänderungs-Benachrichtigungen an die Mitglieder des Baums, die dann ihre STP-Engine neu berechnen müssen, um die neue Änderung zu lernen.
Source MAC: zufällig generiert.
Destination MAC: 01:80:c2:00:00:00
<output from the cisco log>
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
01:35:39: STP: VLAN0001 Topology Change rcvd on Fa0/8
</output>
Unser Ziel ist es nun, die Root-Rolle des Baums zu erlangen. Wie erreichen wir das? Indem wir einfach das Netzwerk abhören, um herauszufinden, wer die Root-Rolle hat, und dann eine conf BPDU mit niedrigerer Priorität senden, um Root zu werden.
Source MAC: dieselbe wie die abgehörte BPDU.
Destination MAC: dieselbe wie die abgehörte BPDU.
Bridge ID: die abgehörte, leicht modifiziert, um eine niedrigere Priorität zu haben
Root ID: 8000: dieselbe wie Bridge-ID.
Hello time: dieselbe wie die abgehörte BPDU.
Forward delay: dieselbe wie die abgehörte BPDU.
Max age: dieselbe wie die abgehörte BPDU.
Root pathcost: dieselbe wie die abgehörte BPDU.
<output from the cisco log>
01:58:48: STP: VLAN0001 heard root 32769-000e.84d4.2280 on Fa0/8
01:58:48: supersedes 32769-000e.84d5.2280
01:58:48: STP: VLAN0001 new root is 32769, 000e.84d4.2280 on port Fa0/8, cost 19
</output>
Wir geben vor, ein weiterer seltsamer Switch zu sein, der mit STP spielt und unsere Root-ID anpreist :)
Indem wir config BPDUs senden, deren Priorität automatisch dekrementiert wird, können wir unendliche Root-Wahlen im STP-Baum verursachen. Das wäre so ähnlich wie eine Neuauszählung der Wahlstimmen, um den Gewinner zu ermitteln (erinnern Sie sich an Florida?).
<output from the cisco log>
00:20:21: STP: VLAN0001 heard root 32769-000e.84d4.2280 on Fa0/9
00:20:21: supersedes 32769-000e.84d5.2280
00:20:21: STP: VLAN0001 new root is 32769, 000e.84d4.2280 on port Fa0/9, cost 19
00:20:23: STP: VLAN0001 heard root 32769-000e.84d3.2280 on Fa0/9
00:20:23: supersedes 32769-000e.84d4.2280
00:20:23: STP: VLAN0001 new root is 32769, 000e.84d3.2280 on port Fa0/9, cost 19
00:20:25: STP: VLAN0001 heard root 32769-000e.84d2.2280 on Fa0/9
00:20:25: supersedes 32769-000e.84d3.2280
00:20:25: STP: VLAN0001 new root is 32769, 000e.84d2.2280 on port Fa0/9, cost 19
00:20:27: STP: VLAN0001 heard root 32769-000e.84d1.2280 on Fa0/9
00:20:27: supersedes 32769-000e.84d2.2280
00:20:27: STP: VLAN0001 new root is 32769, 000e.84d1.2280 on port Fa0/9, cost 19
00:20:29: STP: VLAN0001 heard root 32769-000e.84d0.2280 on Fa0/9
00:20:29: supersedes 32769-000e.84d1.2280
00:20:29: STP: VLAN0001 new root is 32769, 000e.84d0.2280 on port Fa0/9, cost 19
00:20:31: STP: VLAN0001 heard root 32769-000e.84cf.2280 on Fa0/9
00:20:31: supersedes 32769-000e.84d0.2280
00:20:31: STP: VLAN0001 new root is 32769, 000e.84cf.2280 on port Fa0/9, cost 19
00:20:33: STP: VLAN0001 heard root 32769-000e.84ce.2280 on Fa0/9
00:20:33: supersedes 32769-000e.84cf.2280
00:20:33: STP: VLAN0001 new root is 32769, 000e.84ce.2280 on port Fa0/9, cost 19
00:20:35: STP: VLAN0001 heard root 32769-000e.84cd.2280 on Fa0/9
00:20:35: supersedes 32769-000e.84ce.2280
00:20:35: STP: VLAN0001 new root is 32769, 000e.84cd.2280 on port Fa0/9, cost 19
00:20:37: STP: VLAN0001 heard root 32769-000e.84cc.2280 on Fa0/9
00:20:37: supersedes 32769-000e.84cd.2280
00:20:37: STP: VLAN0001 new root is 32769, 000e.84cc.2280 on port Fa0/9, cost 19
00:20:39: STP: VLAN0001 heard root 32769-000e.84cb.2280 on Fa0/9
00:20:39: supersedes 32769-000e.84cc.2280
00:20:39: STP: VLAN0001 new root is 32769, 000e.84cb.2280 on port Fa0/9, cost 19
</output>
Dieses Mal versuchen wir, den Root-Wahlprozess zu erschöpfen. Wir schaffen es, Root im STP-Baum zu werden, hören aber auf, config BPDUs zu senden, bis max_age Sekunden (normalerweise 20) vergangen sind, was eine neue Wahl erzwingt.
<output from the cisco log>
02:02:43: STP: VLAN0001 heard root 32769-000e.84d4.2280 on Fa0/9
02:02:43: supersedes 32769-000e.84d5.2280
02:02:43: STP: VLAN0001 new root is 32769, 000e.84d4.2280 on port Fa0/9, cost 19
02:03:03: STP: VLAN0001 we are the spanning tree root
02:03:04: STP: VLAN0001 heard root 32769-000e.84d4.2280 on Fa0/9
02:03:04: supersedes 32769-000e.84d5.2280
02:03:04: STP: VLAN0001 new root is 32769, 000e.84d4.2280 on port Fa0/9, cost 19
02:03:04: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:06: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:08: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:10: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:12: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:14: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:16: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:18: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:20: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:22: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:24: STP: VLAN0001 we are the spanning tree root
02:03:24: STP: VLAN0001 heard root 32769-000e.84d4.2280 on Fa0/9
02:03:24: supersedes 32769-000e.84d5.2280
02:03:24: STP: VLAN0001 new root is 32769, 000e.84d4.2280 on port Fa0/9, cost 19
02:03:24: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:26: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:28: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:30: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:32: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:34: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:36: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:38: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:40: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:42: STP: VLAN0001 sent Topology Change Notice on Fa0/9
02:03:44: STP: VLAN0001 we are the spanning tree root
</output>
Verwenden Sie Port Security und deaktivieren Sie STP auf den Ports, die kein STP benötigen. Informationen zur Port Security finden Sie unter folgender URL: http://www.cisco.com/en/US/products/hw/switches/ps628/products_configuration_guide_chapter09186a0080150bcd.html
Wenn Sie die Portfast-Funktion in Ihrer STP-Konfiguration verwenden, aktivieren Sie auch die BPDU Guard, um diese Angriffe zu vermeiden, wenn der Port automatisch in den Forwarding-Zustand wechselt: http://www.cisco.com/warp/public/473/65.html
Verwenden Sie die Root Guard-Funktion, um zu verhindern, dass nicht autorisierte Geräte Root werden: http://www.cisco.com/en/US/tech/tk389/tk621/technologies_tech_note09186a00800ae96b.shtml
Guillermo Marros Masterarbeit: http://seclab.cs.ucdavis.edu/papers/Marro_masters_thesis.pdf
Oleg K. Artemjev, Vladislav V. Myasnyankin. Fun with the Spanning Tree Protocol http://phrack.org/issues/61/12.html
Cisco-Geräte haben schon immer eine andere Sprache gesprochen, um miteinander zu kommunizieren, um allen mitzuteilen, dass sie am Leben sind und welche nützlichen Funktionen sie haben. CDP steht für Cisco Discovery Protocol. Mit dieser besonderen Sprache erschaffen Cisco-Geräte eine virtuelle Welt, in der alle glücklich sind und es überhaupt keine Kriminalität gibt. Oder zumindest scheint es so, da viele Netzwerkadministratoren sich noch keine Sorgen um CDP machen. Obwohl einige Informationen, die in einem CDP-Paket gesendet werden können, noch undokumentiert sind (CDP ist ein proprietäres Protokoll, und es scheint, dass Cisco keine Details dazu preisgeben möchte), ist mindestens ein alter Angriff (der noch gültig ist) bekannt, und es gibt eine öffentliche Implementierung (FX hat es gemacht!).
Dieser Angriff ist ein DoS, der versucht, den Gerätespeicher so zu erschöpfen, dass er für keinen Geräteprozess mehr Speicher zuweisen kann. Wie machen wir das? Einfach durch Senden von CDP-Paketen mit gefälschten Daten, die reale Cisco-Geräte simulieren. Das Zielgerät beginnt, Speicher in seiner CDP-Tabelle zuzuweisen, um die Informationen des neuen Nachbarn zu speichern, ohne zu wissen, dass es Tausende oder Millionen neuer Freunde haben wird.
Eine weitere im aktuellen Code implementierte Angriffsmöglichkeit ist die Fähigkeit, ein neues virtuelles Cisco-Gerät zu erstellen, das nur dazu bestimmt ist, ein wenig Chaos zu stiften und zu versuchen, Netzwerkadministratoren zu verwirren.
Screenshot des laufenden Angriffs:
Ausgabe eines Cisco 2503 Routers:
athens#sh mem
Head Total(b) Used(b) Free(b) Lowest(b) Largest(b)
Processor 4873C 3893444 3893444 0 0 0
I/O 400000 2097152 2097088 64 64 64
<log>
%SCHED-3-THRASHING: Process thrashing on watched queue 'CDP packets' (count 57).
-Process= "CDP Protocol", ipl= 6, pid= 9
-Traceback= 3159232 31594DE 3201660
%LANCE-5-COLL: Unit 0, excessive collisions. TDR=7
%SCHED-3-THRASHING: Process thrashing on watched queue 'CDP packets' (count 57).
-Process= "CDP Protocol", ipl= 6, pid= 9
-Traceback= 3159232 31594DE 3201660
%SYS-2-MALLOCFAIL: Memory allocation of 100 bytes failed from 0x3201B3E, pool Processor, alignment 0
-Process= "CDP Protocol", ipl= 0, pid= 9
-Traceback= 314E8A4 314FA06 3201B46 32016C8
%SCHED-3-THRASHING: Process thrashing on watched queue 'CDP packets' (count 57).
-Process= "CDP Protocol", ipl= 6, pid= 9
-Traceback= 3159232 31594DE 3201660
%SYS-2-MALLOCFAIL: Memory allocation of 100 bytes failed from 0x3201B3E, pool Processor, alignment 0
-Process= "CDP Protocol", ipl= 0, pid= 9
-Traceback= 314E8A4 314FA06 3201B46 32016C8
%SYS-2-MALLOCFAIL: Memory allocation of 100 bytes failed from 0x3201B3E, pool Processor, alignment 0
-Process= "CDP Protocol", ipl= 0, pid= 9
-Traceback= 314E8A4 314FA06 3201B46 32016C8
</log>
Und ein paar Minuten später, nachdem der Angriff beendet wurde, hängt der Router überraschenderweise für mehrere Sekunden und wirft einen dann aus dem Terminal :)
<log>
%SYS-3-CPUHOG: Task ran for 16884 msec (69/69), Process = Exec, PC = 3158D42
-Traceback= 3158CEE 3158D4A 30F7330 30F742A 30FF3A4 30FEF76 30FEF1C 3116860
</log>
Ausgabe eines Cisco 2950 Switches:
00:06:08: %SYS-2-MALLOCFAIL: Memory allocation of 224 bytes failed from 0x800118D0, alignment 0
Pool: Processor Free: 0 Cause: Not enough free memory
Alternate Pool: I/O Free: 32 Cause: Not enough free memory
-Process= "CDP Protocol", ipl= 0, pid= 26
-Traceback= 801DFC30 801E1DD8 800118D8 80011218 801D932C 801D9318
00:06:08: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:09: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:10: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:11: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:12: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:13: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:14: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:15: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:16: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:17: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:18: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:19: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:20: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:21: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:22: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:23: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:38: %SYS-2-MALLOCFAIL: Memory allocation of 140 bytes failed from 0x801E28BC, alignment 0
Pool: Processor Free: 0 Cause: Not enough free memory
Alternate Pool: I/O Free: 32 Cause: Not enough free memory
-Process= "Calhoun Statistics Process", ipl= 0, pid= 21
-Traceback= 801DFC30 801E1DD8 801E28C4 801F13BC 801F1470 802F7C90 802F9190 802F9788 801D932C 801D9318
00:06:38: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:39: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:40: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:41: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:42: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:44: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:45: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:46: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:47: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:48: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:49: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:50: ../src-calhoun/strata_stats.c at line 137: can't not push event list
00:06:59: %SYS-3-CPUHOG: Task ran for 2076 msec (11/10), process = Net Background, PC = 801ABD40.
-Traceback= 801ABD48 801D932C 801D9318
Und dann ist der CDP-Prozess komplett down, selbst wenn wir den Angriff stoppen. Keine CDP-Babys mehr...