Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Router Advertisement DoS - [How to exploit] filter_list
Author
Message
Router Advertisement DoS - [How to exploit] #1
Yes. This is more of a guide than a tutorial.


Introduction

So, yes, hello. I will be informing you on a very powerful DoS attack that effects many many systems, for example: <=Windows 7 are vulnerable, as well as many other OS on various devices. And, as far as I am aware, there has been no patch released for this quite old vulnerability.


The vulnerability

The vulnerability exists in the idea of, the pretty redundant, IPV6 (Internet Protocol Version 6), which practically all (most) devices use nowadays, instead of IPV4. Now, let's get down and dirty: when you are connected to your LAN (and assuming you are using IPV6), your router will force your PC to connect to it via Router Advertisement (self-explanatory name), the obvious and legitimate reason this exists is so your system knows what device is the router.


Exploiting

Now, you may be wondering: "Cool, but what does this have to do with hacking?", you probably aren't wondering that at all. Well, what you can do is, if you notice that I said "packets" earlier, now assuming you have basic knowledge on how computers transfer data, you would know they send this data in/as 'packets'. What you can do is send to all of the devices on your LAN packets with false hosts (so the devices receiving the packets will instantly connect to the IP specified in the packet).

But this would make the device try to connect to one IP, right? Well, if you send one packet, yes. But, imagine sending a couple thousand with different hosts to connect to - that would cause all of the vulnerable devices on that network to crash (as they would have too many devices to connect to).

Now, exploiting this vulnerability in your local: coffee shop, school, college, etc, a place with 1-100+ of devices connected to the network would be what I would call a successful attack. This is a very, very, good type of local DoS that I would recommend when attacking a local network, using IPV6.


Prevention

There are a few ways you can prevent this DoS:
  • Use a Linux distribution (not FreeBSD though, it is too vulnerable) or another OS that is not vulnerable to this.
  • Use IPV4.
  • Turn off Router Discovery.
  • Set a firewall rule.
  • Etc


For more details, visit: http://samsclass.info/ipv6/proj/RA_flood2.htm

Reply

RE: Router Advertisement DoS - [How to exploit] #2
(04-02-2013, 06:25 PM)amus3d Wrote: ...

when you are connected to your LAN (and assuming you are using IPV6), your router will force your PC to connect to it via Router Advertisement (self-explanatory name),

...

recommend when attacking a local network, using IPV6.

...


Prevention
  • Use IPV6.


Yay contradictions.


And this isn't really an exploit on any OS, it has more to do with the network than the OS.

Reply

RE: Router Advertisement DoS - [How to exploit] #3
(04-02-2013, 09:23 PM)w00t Wrote: Yay contradictions.


And this isn't really an exploit on any OS, it has more to do with the network than the OS.

1. can't understand typo.
2. no it doesnt exploit every os, obviously.
3. "it has more to do with the network than the OS" - no. some systems are vuln and some arent.

you are not the brightest skid on the block btw.

Reply

RE: Router Advertisement DoS - [How to exploit] #4
There isn't a single typo, but okay.

You don't understand what a DoS is. The main problem with this attack is not the amount of data that the target receives, but the amount they then try to send out. Some OSs crash, sure, but the target will still find their computer and network unusable if they have router discovery on.

Reply

RE: Router Advertisement DoS - [How to exploit] #5
(04-03-2013, 04:55 AM)w00t Wrote: There isn't a single typo, but okay.

You don't understand what a DoS is. The main problem with this attack is not the amount of data that the target receives, but the amount they then try to send out. Some OSs crash, sure, but the target will still find their computer and network unusable if they have router discovery on.

there was a typo and i corrected it.

i do understand what a dos is, none of the skids here do though; they all think it is big DD0S sh3lls, no whammis3s and shit, when it isnt.

the vulnerability exists in the way that the packets from router advertisements are recieved, example: windows (vulnerable versions), just attempt to connect to all of the hosts and shit, for OSX (non vulnerable versions - i dont think any are vuln), as they connect to a few hosts then just ignore the rest.


hurr durr.

Reply

RE: Router Advertisement DoS - [How to exploit] #6
(04-03-2013, 10:31 AM)vipvince Wrote: Neither skidmused or w00t have a clue whatsoever about the gibberish they are spitting out, watching two skids try to act like they know something, pretty cute.

WHO ARE YOU? please tell me. i am confounded.
talk shit to me and i will get you.

i mean it. fear me, pls...

Reply

RE: Router Advertisement DoS - [How to exploit] #7
(04-02-2013, 09:23 PM)w00t Wrote: And this isn't really an exploit on any OS, it has more to do with the network than the OS.
This only works for winblows, OP probably just watched some dumb ass on youtube or some idiot on a blog write about this. WINDOWS connects with RA.

Reply

RE: Router Advertisement DoS - [How to exploit] #8
Does this just attack the LAN network or a targetted site? Sorry if i sound dumb, i'm out of it today.

Reply

RE: Router Advertisement DoS - [How to exploit] #9
I suppose this would not work for targeting individual targets from what I have read up so far.... Unless you force a fake AP, which pretty much defeats the purpose all together of using this for an attack.

Anyone know of any good local DOS that doesn't rely on large packet counts(the less packets to the router, the better). ??

Reply

RE: Router Advertisement DoS - [How to exploit] #10
This is really old and patched on 90% of the newer routers and systems.

Reply







Users browsing this thread: 1 Guest(s)