The firewall at the edge of the network, however well configured, sees absolutely nothing of what happens between two computers in the same room. Their traffic never crosses it. This lecture deals with exactly that blind spot: the attacks that work inside the local network, almost all of them exploiting mechanisms we built ourselves, in lectures 3 and 4, and which do exactly what they were designed to do. We shall not repair the protocols - that cannot be done. We shall add around them the checks they lack.
1From the switching lectures5 min
- A switch learns MAC addresses from the source field of the frames it receives.
- The CAM table has a finite size; whatever is not found in it is flooded on every port.
- ARP associates an IP address with a MAC address, by asking through broadcast.
- The native VLAN travels untagged over a trunk.
- STP elects as root the switch with the lowest Bridge ID.
- DHCP works through broadcast; the client accepts the first offer to arrive.
Every one of these six sentences is, today, the starting point of an attack. Not because they are wrongly implemented, but because they are implemented exactly as they were conceived - in an age when the local network was, implicitly, a space of trust.
Learning outcomes
- Classify an attack by its purpose and say which mechanism it exploits
- Explain the mechanics of CAM overflow, ARP poisoning and VLAN hopping
- Describe how a single cable can bring down an entire network through STP
- Configure port security, DHCP snooping and Dynamic ARP Inspection
- Close VLAN hopping through three settings
- Explain what a salt does and, above all, what it does not do
- Apply a complete hardening list to an access switch
2Three families of attack8 min
A firewall sits between two networks and sees only the traffic that crosses it.
If host A and host B are in the same VLAN, on the same switch, the traffic between them never reaches a router, and so never reaches the firewall. The switch forwards it directly, at layer 2.
Every attack in this lecture is conducted below the level at which a classic firewall looks. The defence must be there too - on the switch.
| Family | Purpose | Examples in a LAN |
|---|---|---|
| Reconnaissance | finding out what exists and what is running | ping sweep, port scan, sniffing, DNS queries |
| Denial (DoS) | making a service unavailable | SYN flood, smurf, CAM overflow, STP attack |
| Access | obtaining undeserved privileges | ARP poisoning, VLAN hopping, password cracking, social engineering |
ARP authenticates nothing - by design. A switch believes any source MAC - by design. STP accepts any BPDU - by design. DHCP accepts the first offer - by design.
All of them were conceived in an age when being physically connected to the network meant being trusted. The countermeasures do not repair the protocols; they add around them the checks that are missing.
The firewall is reception. The measures in this lecture are the locks on the internal doors - and the reason they are called, collectively, defence in depth.
3Reconnaissance9 min
Before any serious attack comes the gathering of information: which IP addresses are alive, what services run on them, in what version, what operating systems, and whom the users of the network trust.
The same tools are used daily by administrators too - the difference is the authorisation, not the instrument.
| Utility | What it does | Example |
|---|---|---|
nmap | discovers live hosts, open ports, services, versions, operating system | nmap -sV 192.168.1.0/24 |
tcpdump | traffic capture from the command line, with filters | tcpdump -i eth0 -c 10 dst port 80 |
Wireshark | graphical capture and analysis; requires the interface in promiscuous mode | libpcap format, shared with tcpdump |
whois | administrative information about a domain | whois example.com |
host, dig | DNS queries: name servers, mail servers | host -t MX example.com |
Scanning or intercepting somebody else's traffic - even on the same network, even "just to see whether it works" - is illegal and punishable. The purpose of this course is that you should understand what an attacker sees, so that you can build the defence; not that you should practise on other people's systems.
Look at the third command. Two different IP addresses with the same MAC address is the anomaly that betrays a man-in-the-middle attack - and it is the cheapest check you can make on a suspect host.
What a firewall can do against reconnaissance: block the answer to ICMP echo, close vulnerable ports, forbid connections being initiated from outside, limit the rate of requests. What it cannot do: stop an attacker already inside the local network. Hence the rest of the lecture.
4Denial-of-service attacks9 min
The smurf attack
TCP SYN flood
We met it in lecture 8: the attacker sends thousands of SYN segments with forged source addresses, and the server allocates an entry in the queue of half-open connections for each. When the queue fills, legitimate connections are refused.
Defences: SYN cookies, which let the server allocate nothing until confirmation; limiting the number of half-open connections per source; and, as always, monitoring the traffic under normal conditions - an anomaly is noticed only if you know what normal looks like.
5CAM overflow10 min
This is the attack that directly exploits the mechanism from lecture 3. A switch's memory is finite - typically between 8,000 and 32,000 entries - so the CAM table can be filled. And when it fills, the switch can no longer learn new addresses and floods every unknown frame on every port. In other words: it becomes a hub again.
Go back to the CAM table simulator from lecture 3 and watch what happens with every frame: the switch learns only from the source address and floods any unknown destination. The attack does nothing but push those two rules to their limit.
SW(config)# interface fastEthernet 0/5 SW(config-if)# switchport mode access SW(config-if)# switchport port-security SW(config-if)# switchport port-security maximum 2 SW(config-if)# switchport port-security mac-address sticky SW(config-if)# switchport port-security violation restrict SW(config-if)# switchport port-security aging time 60 SW# show port-security interface fastEthernet 0/5 SW# show mac address-table count
| Action on violation | What it does | When to use it |
|---|---|---|
protect | silently discards the excess frames | rarely - you never find out that anything happened |
restrict | discards, increments a counter, sends SNMP and syslog | the recommended default |
shutdown | shuts the port down (err-disable) | sensitive areas; requires manual intervention or errdisable recovery |
sticky means
Addresses learned dynamically are written automatically into the running configuration, as though you
had entered them by hand. The advantage: you do not have to know every computer's address in
advance.Beware, however: if you do not save the configuration, they are lost on reboot - and if you do save them, the port stays tied to that particular computer, which becomes a problem the first time a machine is replaced.
6Man-in-the-middle through ARP poisoning11 min
ARP, as we studied it in lecture 5, has a property that today seems inconceivable: it authenticates nothing. What is more, most implementations accept an ARP reply even if they never sent a request - a mechanism called gratuitous ARP, useful for announcing an address change, but exploitable.
! 1. the switch learns which IP address each port received, through DHCP SW(config)# ip dhcp snooping SW(config)# ip dhcp snooping vlan 10,20 SW(config)# interface gigabitEthernet 0/1 SW(config-if)# ip dhcp snooping trust ! 2. on the basis of that record, every ARP message is checked SW(config)# ip arp inspection vlan 10,20 SW(config)# interface gigabitEthernet 0/1 SW(config-if)# ip arp inspection trust ! 3. for hosts with a static address, the record is written by hand SW(config)# arp access-list SERVERS SW(config-arp-nacl)# permit ip host 192.168.1.50 mac host 000c.2911.2233 SW(config)# ip arp inspection filter SERVERS vlan 10 SW# show ip dhcp snooping binding SW# show ip arp inspection statistics
Untrusted ports are not allowed to send server messages (Offer, Ack), so the attack never even starts. One command, two attacks closed.
7VLAN hopping11 min
We built VLANs precisely in order to isolate departments. There are two techniques by which the isolation can be got round - both exploiting default behaviours of switches.
Switch spoofing
Many Cisco switches have DTP (Dynamic Trunking Protocol) enabled by default, which automatically negotiates whether a port becomes access or trunk. An attacker can present themselves as a switch and negotiate a trunk. Once obtained, they can send and receive 802.1Q-tagged frames for any VLAN.
SW(config)# interface range fastEthernet 0/1 - 22 SW(config-if-range)# switchport mode access SW(config-if-range)# switchport nonegotiate SW(config-if-range)# switchport access vlan 10 ! unused ports: shut down and moved into a dead VLAN SW(config)# interface range fastEthernet 0/23 - 24 SW(config-if-range)# switchport access vlan 999 SW(config-if-range)# shutdown
Double tagging
The technique exploits the native VLAN, which we know from lecture 4 travels untagged over a trunk. It requires no special protocol on the attacker's side - only the ability to build a frame with two tags.
2. Make access ports explicitly
switchport mode access with
switchport nonegotiate.3. On trunks, declare the list of allowed VLANs explicitly (
switchport trunk allowed vlan 10,20,30), rather than leaving it at the default of
"all".8Attacks against STP10 min
STP uses no form of authentication whatever: any device that sends BPDUs takes part in the root election. An attacker connected anywhere in the network can announce BPDUs with a very low Bridge ID and become the root bridge - at which point a considerable part of the traffic begins to pass through them.
Lower the priority of a switch to 0 in the simulator above and watch the whole topology reorganise itself around it. That is exactly what the attacker does - except that the switch with priority 0 is their laptop, under the desk.
- The attacker connects to the switched network, with a single cable.
- They announce BPDUs with priority 0, hence with the lowest possible BID.
- STP reconverges; they become the root, and the port roles are recomputed around them.
- Traffic between segments now passes through their machine, where it can be captured.
The denial-of-service variant is simpler still: the attacker changes their BID continually, forcing permanent recomputations. The ports never reach the forwarding state, and the network is, in practice, stopped - with one cable and no exploit at all.
! ports towards hosts: go straight into forwarding... SW(config)# interface range fastEthernet 0/1 - 22 SW(config-if-range)# spanning-tree portfast ! ...and shut down if a BPDU appears from there SW(config-if-range)# spanning-tree bpduguard enable ! the root is set explicitly, on the switch at the centre of the network SW_CORE(config)# spanning-tree vlan 1-100 root primary ! ports towards switches that must not become the root SW(config)# interface gigabitEthernet 0/2 SW(config-if)# spanning-tree guard root ! automatic reactivation of shut-down ports, after 5 minutes SW(config)# errdisable recovery cause bpduguard SW(config)# errdisable recovery interval 300
| Mechanism | What it does | Where it goes |
|---|---|---|
| PortFast | skips listening and learning on access ports | ports towards hosts; never towards switches |
| BPDU Guard | shuts the port down if it receives a BPDU | together with PortFast, always |
| Root Guard | prevents a port from becoming a root port | on ports towards switches that must not be the root |
| BPDU Filter | stops the sending and receiving of BPDUs entirely | rarely; to be used with caution, it can create loops |
The two always go together. The mnemonic: PortFast promises there is no switch there; BPDU Guard checks the promise.
9Passwords, hashes and salt9 min
| Method | How it works | Countermeasure |
|---|---|---|
| Sniffing | passwords sent in the clear (Telnet, FTP, HTTP) are read straight out of the traffic | SSH, HTTPS - anything encrypted |
| Brute force | every possible combination is tried | long passwords; limiting the attempts |
| Dictionary attack | common words and simple variations of them are tried | passwords that are not words |
| Rainbow tables | chains of precomputed hashes, trading space for time | salt |
A hash is a one-way function: it is computed instantly from the password, but from the result the password cannot be recovered.
The server stores only the hash. At authentication it computes the hash of the password entered and compares. If the database is stolen, the attacker does not have the passwords - only the hashes.
The problem: if two users have the same password, they also have the same hash. And an attacker can precompute the hashes of the few million commonest passwords and look them up directly. This is where rainbow tables come in.
A rainbow table does not store every possible hash - that would be impossible - but the starting points of chains of hashes, from which the intermediate values are recomputed as needed. It is a classic memory-time trade-off, and public tables of thousands of gigabytes are available on the Internet.
The salt
A salt is a random segment, generated for each user and concatenated to the password before hashing. It is stored alongside the hash, in the clear - it is not secret and does not need to be.
trudy:$6$/tKy92iM$/.cIxbEX49qHpZt74D5L0W1vXO2fJuXjyXJnsT0.M... # ^ ^ ^ # | | the hash itself # | the salt, randomly generated # the algorithm: 6 = SHA-512
What it does: it forces the attacker to build a new table for every individual user - which turns a few-minute attack on the whole database into a separate effort per account. And it makes two users with the same password have different hashes.
It is a measure of scale, not of impossibility: a weak password stays weak with a salt too. For real resistance, deliberately slow functions are used - bcrypt, scrypt, Argon2 - which make each attempt expensive.
10The human factor and hostile code7 min
Social engineering
The most effective avenue of access is not technical. The attacker convinces a person that they are trustworthy - a colleague from IT, a supplier, a superior in a hurry - and obtains the information directly. The target usually has no technical background, wants to help, and does not realise the value of what they hold.
Social engineering bypasses any technical mechanism, however well configured. There is no port security for a telephone. The only real defence is periodic training of non-technical staff and the existence of clear procedures for unusual requests - for instance, the rule that a password is never given out over the telephone, whoever is calling.
Phishing is the industrialised version of the same idea: instead of one call, a million messages.
Hostile executable code
| Type | How it spreads | What characterises it |
|---|---|---|
| Virus | attached to a program; it needs the user to run it | a direct effect, often visible |
| Trojan | hidden inside an apparently useful application | a subtle effect - usually it opens a back door; hard to detect |
| Worm | exploits vulnerabilities; it does not need a user | very rapid spread; it often builds botnets |
| Ransomware | any of the routes above | encrypts the data and demands a ransom; it spreads laterally within the LAN |
VLANs, the ACLs between them and the measures in this lecture do not prevent the initial infection - but they dramatically limit how far it gets. That is the difference between an incident and a disaster.
11The short list for hardening a switch8 min
Everything discussed above comes down to a few configurations that apply to any access switch, in any organisational network.
| Measure | Against what |
|---|---|
port-security with maximum and sticky | CAM overflow, unauthorised devices |
ip dhcp snooping | rogue DHCP servers |
ip arp inspection | ARP poisoning, man-in-the-middle |
switchport mode access + nonegotiate | switch spoofing |
| an unused native VLAN, explicitly allowed VLANs | double tagging |
portfast + bpduguard | STP attacks |
unused ports: shutdown, in a dead VLAN | unauthorised connections |
| SSH instead of Telnet, with an ACL on the VTY lines | interception of management passwords |
SW(config)# hostname SW1 SW(config)# ip domain-name networks.local SW(config)# crypto key generate rsa modulus 2048 SW(config)# ip ssh version 2 SW(config)# username admin privilege 15 secret AStrongPassword SW(config)# service password-encryption SW(config)# access-list 20 permit 10.0.100.0 0.0.0.255 SW(config)# line vty 0 15 SW(config-line)# transport input ssh SW(config-line)# login local SW(config-line)# access-class 20 in SW(config-line)# exec-timeout 5 0
12Common mistakes4 min
- "I put portfast on every port, towards switches included" A loop can form before STP reacts - and a layer 2 loop stops the network within seconds. PortFast only towards hosts, always with BPDU Guard alongside.
- "I enabled DAI, and now the servers with static addresses cannot communicate"
DAI relies on the record built by DHCP snooping. A host that never used DHCP does not appear
there.
Add manual entries with
arp access-listfor the servers with fixed addresses. - "I set port-security maximum 1 everywhere" An IP telephone with a PC behind it has two addresses; a bridged virtual machine adds more. Choose the maximum from what actually connects there. 2 or 3 is more realistic.
- "I left VLAN 1 as the native VLAN" It is the default value and, often, the very VLAN the hosts are in - the exact precondition of the double tagging attack. A dedicated, empty native VLAN, different from 1 and from any user VLAN.
- "I configured everything, but did not save"
The sticky addresses and the whole configuration disappear at the first reboot.
copy running-config startup-config. The same lesson as in lecture 6. - "Port security with violation shutdown, and now half the ports are shut"
A user who changes their laptop shuts the port, and reactivating it requires manual
intervention.
restrictfor ordinary areas;errdisable recoverywhere you do useshutdown. - "We have a firewall, so the internal network is safe" The firewall does not see the traffic between two hosts in the same VLAN. Defence in depth: segmentation, measures on the switch, end-to-end encryption.
13Summary and glossary5 min
- The edge firewall does not see the traffic inside a VLAN.
- Almost every LAN attack exploits protocols that are working correctly.
- CAM overflow forges source MAC addresses → closed with
port-security. - ARP poisoning exploits the absence of authentication in ARP → closed with DHCP snooping + DAI.
- Switch spoofing exploits DTP →
nonegotiate. - Double tagging exploits the native VLAN → an unused native VLAN.
- The STP attack exploits the absence of BPDU authentication → PortFast + BPDU Guard.
- The salt does not strengthen the password: it forces the attacker into one table per account.
- Social engineering bypasses every technical measure. It is defended against with procedures and training.
- Security is in depth: no single measure is enough.
14Self-check questions7 min
15Closing2 min
With this lecture the course comes to a close. We started, in lecture 1, from an electrical signal on a wire and the question of how a bit becomes a voltage. We have arrived at a local network segmented into VLANs, dynamically routed, filtered with access lists, translated on the way out, extended without wires and defended against the attacks from within it.
What is worth keeping, beyond the commands: almost every mechanism we studied was invented as the solution to a concrete problem, and almost every one later became somebody else's problem. The switch solved collisions and created CAM overflow. The VLAN solved broadcast and created VLAN hopping. NAT rescued IPv4 and broke peer-to-peer. There is no design decision without a cost - there are only decisions taken knowingly and decisions taken out of habit.
Laboratory 7 carries out, under control, three of the attacks from here and then closes their doors, one by one.
- Cisco - Catalyst Switch Security Configuration Guide: port security, DHCP snooping, DAI
- RFC 2827 / BCP 38 - ingress filtering against address spoofing
- RFC 3704 - ingress filtering for multihomed networks
- OWASP - resources on passwords, hashing and authentication
- The
nmapandWiresharkdocumentation - for strictly authorised use