Security Basics mailing list archives
RE: ARP spoofing attacks
From: "David Gillett" <gillettdavid () fhda edu>
Date: Wed, 14 Apr 2004 16:47:43 -0700
The short, sharp, general answer is that you can't. Layer two security measures are going to see a packet (it happens to be an ARP reply) from the miscreant's port, but since its source MAC address is what they expect, they'll let it through. Layer three measures won't see it either, because it's a unicast within the same vlan/subnet and so never needs to hit a layer 3 device. About all you can do proactively, if this is a serious concern, is add a static ARP table entry to every host so they never need to send out an ARP request for the gateway. David Gillett
-----Original Message----- From: Amit Agrawal [mailto:csu02103 () cse iitd ernet in] Sent: Tuesday, April 13, 2004 9:22 PM To: security-basics () securityfocus com Subject: ARP spoofing attacks Hi I have a question...How do u secure against ARP spoofing attacks...If not the whole subnet...I want to be sure that no one spoofs the IP of my gateway. Amit
--------------------------------------------------------------------------- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ----------------------------------------------------------------------------
Current thread:
- syslog GUI for Linux Omar Khawaja (Apr 08)
- Re: syslog GUI for Linux Daniel Cid (Apr 12)
- ARP spoofing attacks Amit Agrawal (Apr 14)
- Re: ARP spoofing attacks Chris Moody (Apr 15)
- Re: ARP spoofing attacks Matthias Vallentin (Apr 16)
- Re: ARP spoofing attacks Chris Moody (Apr 19)
- Re: ARP spoofing attacks Markus Schabel (Apr 19)
- ARP spoofing attacks Amit Agrawal (Apr 14)
- Re: ARP spoofing attacks die tuere (Apr 15)
- RE: ARP spoofing attacks David Gillett (Apr 15)
- Re: ARP spoofing attacks Markus Schabel (Apr 16)
- RE: ARP spoofing attacks Ranjeet Shetye (Apr 16)
- Re: syslog GUI for Linux Daniel Cid (Apr 12)
- Re: syslog GUI for Linux Daniel Cid (Apr 21)
- Filtering SPAM with Linux ivan.hernandez (Apr 27)
- Re: Filtering SPAM with Linux Rajeev Kumar (Apr 27)
- RE: Filtering SPAM with Linux Sanjay K. Patel (Apr 27)
- Re: Filtering SPAM with Linux Gene Cronk (Apr 27)
- Message not available
- Re: Filtering SPAM with Linux Ivan Hernandez (Apr 28)