As promised the second part in our series on utilizing Yersinia to exploit insecure network infrastructure designs. This blog focuses on VLAN hopping. First let me say that early on in my pilgrimage to security enlightenment and network utopia (not that I am there yet) I was guilty of the same pitfall that many organizations continue to believe. That belief being, that VLANs are a way to secure network segments. Unfortunately that is not the case. VLANs are purely a way to segment traffic. With strong access lists and port controls they will help to assist in increasing network security, but as a stand alone item they have nothing to do with security. Readers flame on.
With this in mind lets exam how to exploit the unsubstantiated belief that VLANs will secure independent network segments. To do this once again we will go to our wonderful friends in Spain, David and Alfredo and their great tool Yersinia.
Connect your system locally to the switched infrastructure that you would like to exploit. Fire up Yersinia in its graphical mode “yersinia –I” from your beast of a linux machine. Because as the boys in Spain say when asked about a Windows version. “ No, it does certainly not. Perhaps some nice fellow could port yersinia to Windows and make you happy.”
Read the rest of this entry »