Re: Frame relay security

From: cbrenton (cbrentonat_private)
Date: Mon Apr 20 1998 - 20:45:08 PDT

  • Next message: Jeff Sedayao: "Re: When to do something about detected attacks (was Re: how to do...)"

    On Mon, 20 Apr 1998, Lyndon David wrote:
    
    > They said, we asked our frame relay provider if they are secure and they
    > said yes and we believe them. 
    
    <EG> Yup, ask any vendor, they'll tell you the same. Can you imagine them
    telling you otherwise?
    
    This is a process issue. If I develop something, of course I'm going to
    tell you it is secure unless I know I've created a back door. This does
    not mean that someone will not catch something else that I've missed.
    
    > So to cut a long and tedious conversation short I would very much like
    > to hear from anyone stories of how frame relay connections have been
    > tampered with so that the traffic can be listened to. Listening is
    > enough, the data does not have to be changed.
    
    I've done this by accident myself and I think someone mentioned to me that
    there is an article over on Phrack. Just change the DLCI number of your
    connection to another number used by someone else on the same switch.
    You'll start receiving a copy of all their inbound frames.
    
    If this does not convince them, describe what "public network" means. ;)
    
    Cheers,
    Chris
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 12:55:47 PDT