Home | Sitemap | Links | Set as homepage | Add to favorites
Search the Site     » Advanced
Sections
Syndication
Newsletter



Looking For Casino Bonus? Get it Now!
The new Bonus Software is out! Access more than ,000 in free casino money, Just enter your email address and open the door to a world of Online casinos! 100% FREE. US Players Welcome!
www.eplayerscard.com - 1.35

^0 FREE at Vegas-Millions Casino!^
The Long Awaited Brand is Finally Out. Play Over a Hundred of the Newest Games. Get 0 Bonus to Play with, and Keep the Winnings to Yourself! Zero Risk, US Players Welcome!
www.vegas-millions.com/lasvegas.html - 1.35

0,000 Anyone? Slot Game Tournaments!
Enter your mail to gain access to Exclusive Online Slot Tournaments & Bonuses + Free Download of ePlayersCard - the Bonus Software that will Change Your Life! US Players Welcome.
www.allslots-online.com - 1.35

0 Free Bonus - Platinum Play Casino
Platinum Play Casino is offering an amazing 0 FREE welcome bonus. Learn more
www.blackjack-strategycard.com - 0.94

Best Online Gambling & Casino Bonuses
The latest Casino reviews and Ranking for the best gambling bonuses online. Play Safe, Secure, Exciting games - 00's of FREE Casino bonuses listed - U.S Friendly Casinos - Learn more
www.gamblingprophet.com - 0.85

Cisco Ccnp Certification / Bcmsn Exam: Defending Against Vlan Hopping Attacks

Spead the word...

Jul 14,2007 by shab

image
During our Cisco CCNP BCMSN certification exam preparation, we've seen how intruders can use seemingly innocent ARP and DHCP processes can be used to harm our network, so it shouldn't come as any surprise that Dot1q tagging can be used against us as well!

One form of VLAN Hopping is double tagging, so named because the intruder will transmit frames that are "double tagged" with two separate VLAN IDs. As you'll see in our example, certain circumstances must exist for a double tagging attack to be successful:


The intruder's host device must be attached to an access port.

The VLAN used by that access port must be the native VLAN.

The term "native VLAN" tips us off to the third requirement - dot1q must be the trunking protocol in use, since ISL doesn't use the native VLAN.

When the rogue host transmits a frame, that frame will have two tags. One will indicate native VLAN membership, and the second will be the number of the VLAN under attack. In this example, we'll assume that to be VLAN 100, with the native VLAN set as VLAN 25.

The trunk receiving this double-tagged frame will see the tag for VLAN 25, and since that's the native VLAN, that tag will be removed and then transmitted across the trunk - but the tag for VLAN 100 is still there!

When the switch on the other side of the trunk gets that frame, it sees the tag for VLAN 100 and forwards the frame to ports in that VLAN. The rogue now has successfully fooled the switches and has hopped from one VLAN to another.

This is why you often see the native VLAN of a network set to a VLAN that no host on the network is a member of - that stops this version of VLAN Hopping right in its tracks.

Notice that I said "this version". We'll take a look at another VLAN Hopping tactic in the next installation of my CIsco CCNP BCMSN certification exam tutorial series!

More Topics:
Boot Camps For Troubled Teens
Provides information to parents with troubled teens on juvenile boot camps and alternatives.

Boot Camps For Teens - Juvenile Bootcamps for Troubled Teens
Are you considering juvenile boot camps? ... camps we work with are very similar to life in an army basic training or boot camp situation. ...

BootCamps.com - Directory Of Boot Camps
Boot Camps original coined as a term for basic training boot camp has evolved to ... The Boot Camps.com directory lists a wide variety of boot camp related sites ...

101 times read

Related news

» How To Choose Right Boot Camps For Troubled Teens
by shab posted on Feb 06,2008
» Profit of Summer Camp
by shab posted on Jun 27,2008
» The Need of Behaviour modification for Teens
by shab posted on Apr 04,2008
» A Quick Guide To Life At Military School
by shab posted on Oct 25,2007
» Booting problem in PC
by shab posted on May 31,2007
Did you enjoy this article?
(total 0 votes)


More Top News
General
News
Auto and Trucks
Business and Finance
Computers and Internet
Family
Food and Drink
Health
Home Improvement
Kids and Teens
Legal Matters
Marketing
Online Business
Parenting
Recreation and Sports
Self Improvement
Site Promotion
Travel and Leisure
Web Development
Women
Writing
Most Popular
Featured Author