This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Home Products Support Community News


Re: [Xen-users] [SECURITY] preventing Hwaddr spoofing on bridge

To: Andy Smith <andy@xxxxxxxxxxxxxx>
Subject: Re: [Xen-users] [SECURITY] preventing Hwaddr spoofing on bridge
From: Stefan de Konink <skinkie@xxxxxxxxx>
Date: Wed, 28 Nov 2007 13:46:34 +0100 (CET)
Cc: xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: Wed, 28 Nov 2007 04:47:19 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <20071128124046.GH3347@xxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
On Wed, 28 Nov 2007, Andy Smith wrote:

> On Tue, Nov 27, 2007 at 03:21:14PM +0100, RafaÅ? Kupka wrote:
> > On Sun, Nov 25, 2007 at 07:50:23AM +0000, Andy Smith wrote:
> > > I see your point.  I hadn't thought of that problem before.  I have
> > > done some preliminary testing with ebtables and the following seems
> > > to work:
> > >
> > > ebtables -t nat -A PREROUTING -i some-vif -s ! aa:00:00:6a:38:0c 
> > > --log-level debug --log-prefix 'SPOOF:' -j DROP
> > >
> > > Can you still find a way to break it after using this method?
> >
> > You can still impersonate other domUs IP addresses. Rooted domUs may
> > send spoofed arp replies with MAC address that belong to them.
> Yes I already addressed that in my earlier reply in this thread.
> The previous one was specifically about spoofing MAC address, which
> I had not considered until Stefan brought it up.

I still need to verify the rules when I have a quiet moment. The problem
with DROP rules is always they need to be in a seperate chain... or
sequence will matter.


Xen-users mailing list