OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: More on ARP cache poisoning
From: Clifford, Shawn A (shawn.a.cliffordLMCO.COM)
Date: Tue Feb 01 2000 - 15:35:35 CST


I tried to see if it would be possible to poison the ARP cache of my machine
(Solaris 2.6) so that it contained an Ether address of a local machine, but
the IP address of a machine outside my network (prep.ai.mit.edu, for
example).

I didn't work. Not with the 'poink' program nor with 'arp -s <host>
<ether>'. The ARP cache in Solaris anyway is smart enough to not take
entries for remote networks. Maybe someone else can try on Linux and other
platforms. I will try under HP-sUX when I get a chance.

So, this pretty much makes moot hijacking the SETI download, etc. You can
ony use the ARP poison to redirect connections _within_ or LAN.

If anybody finds a way around this, please post the solution.

-- Shawn