Re: ATM Switch Vulnerabilities

From: Jose Nazario (joseat_private)
Date: Wed Oct 17 2001 - 12:17:32 PDT

  • Next message: dzzieat_private: "Re: uploading files to Apache webserver"

    On Tue, 16 Oct 2001, Myron L. Cramer wrote:
    
    >    I would appreciate any links or information relative to ATM Switch
    > vulnerabilities or risks, especially anything that works below the IP
    > level.  Thanks.
    
    what kind of ATM? LANE? CLIP? pure ATM?
    
    if its LANE, you can abuse the ARP table size and shove unicasts to the
    BUS, leaking traffic, on some switches, especially edge devices. its not
    pretty. Fore (now marconi) used to have some API code for doing ATM cells
    from the ground up.
    
    just some thoughts. also, a lot of Fore switches ran Solaris. you could
    get in and abuse the switching tables there.
    
    ____________________________
    jose nazario						     joseat_private
    	      	     PGP: 89 B0 81 DA 5B FD 7E 00  99 C3 B2 CD 48 A0 07 80
    				       PGP key ID 0xFD37F4E5 (pgp.mit.edu)
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Wed Oct 17 2001 - 15:02:26 PDT