ARP and DoS

Today I had some free time so I was cleaning my desktop and found my reading shelf folder and it had over 70 files to be read, so I started reading. I came across one whitepaper from DEFCON 15, from Jesse D’ Aguanno. It talked about Forging of ARP packets, I kept on reading and when I finished it opened his homepage for the software to download. Unfortunately I didn’t have linux on my laptop and wasn’t able to find some good software for packet injection. Finally I came across Netwox and from there my R&D started. ;)

  1. Downloaded the binary & installed it.
  2. Scanned the LAN and found some MAC addresses.
  3. Then started injecting some packets.

The end result: I was able to block more than 20 PCs from accessing the internet. What actually happened was I sent ARP Reply packets to the LAN PCs telling them that the gateway 10.0.0.1 had a MAC address ff:00:ff:00:ff:00 which didn’t exist. So whenever they tried to access internet, their packets would be lost.

Accidentally I did this to one of my friends as well, question arised how to make internet accessible to him again? I first asked him to pull out the network cable and try again. But it didn’t work. Then disabled and enabled the network but still no go. Finally he had to restart his PC.

This technique can poision the ARP cache of thousands of PCs in just seconds. I think will study how to stop it tomorrow.

The blocking of internet this way is called DoS Attack i.e., Denial of Service Attack. :)

POSTED BY tarun on 17 April 2008
in Computer Security, Gaming Freaks
Tagged with:

 

Please leave a Comment

If you would like to make a comment, please fill out the form below.

Name (required)

Email (required)

Website

Comments

1 Comment so far

  1. Shantanu Goel said on June 1, 2008 at 2:02:11 am

    You could have simply flushed his computer’s ARP cache, or deleted and rebuilt the affected arp entry,,

© 2005-2008 diGit Blog [Disclaimer]. Content of this Blog Licensed Under Attribution-Share Alike 3.0 Unported
Riding Stoutly on WordPress   ||   Powered by iNetwork.IN
Decorated in GreenTech Theme