OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Nathan Catlow (nscQSF.DEMON.CO.UK)
Date: Wed Feb 07 2001 - 11:49:17 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    In my experience the only successful VLAN breaches I have seen have been
    through insecure methods of VLAN membership (by IP or by MAC address) or by
    getting onto the main backbone and 'joining' VLANS through insecure Gigabit or
    ATM ports oh and of course people leaving 'default' management ports bound to
    the wrong VLAN (usualy the first VLAN configured) which is always a good one.

    I have never seen VLAN breaches by flooding of MAC addresses. This is more
    likely to produce a VLAN to lose it's switching capability but not *all* VLANS
    to start cross populating traffic.

    But hey doesn't mean it's not possible.

    regards,

    Nathan.

    --
    nscqsf.demon.co.uk |  All opinions   | IT Security Specialist
                        |  are my own     |
    

    *I'd love to give my 0.02 worth - Have you got change for a dollar?*