Tools
BackTrack
Yersinia
vconfig
Wireshark
Nmap
I start off by connecting to the LAN and getting a network address
dhclient eth0
data:image/s3,"s3://crabby-images/e27a0/e27a0470e3b4fc3d1552d1ce2e9495e2c9f1e1ef" alt=""
I can see that I'm attached to the network 10.0.1.0/24
Next I fire up wireshark and check the network for DTP (Dynamic Trunking Protocol) frames and CDP (Cisco Discovery Protocol) frames.
data:image/s3,"s3://crabby-images/71745/71745d02cb0f0b91fe938cdd1db97665514764c2" alt=""
I can see that I have both CDP and DTP frames present.
Now I want to tell the switch that my port is a trunk port, for this I'll use Yersinia and tell it to look at DTP.
yersinia -I
data:image/s3,"s3://crabby-images/77ed4/77ed4d396bc941cb2adf9983badc7bcbab7cbfa7" alt=""
After I see DTP frames appear in Yersinia I launch the attack to configure the port for trunking.
data:image/s3,"s3://crabby-images/9bf8f/9bf8fbe2c6e3e3e4e28d0976daf4379066e362f0" alt=""
Now I need to know the VLAN number that other networks are on. Before launching Yersinia I could only see traffic from my own network (10.0.1.0/24), now I can start to see traffic from hosts on another network (192.168.2.2).
data:image/s3,"s3://crabby-images/27089/27089056317f9f15a615d27e03193a1c06991835" alt=""
Looking at the 802.1Q information in the frame I can see that the other network is on VLAN 2.
data:image/s3,"s3://crabby-images/78e6b/78e6b769b7b29d40a19e58bec04c6bc803da12d8" alt=""
With this information I'll create a new interface in the new network and configure vconfig to tag the frames for VLAN2.
vconfig add eth0 2
ifconfig eth0.2 up
ifconfig eth0.2 192.168.2.200/24
ifconfig
data:image/s3,"s3://crabby-images/87e12/87e12c9d3987a587d6317548a523603882fe2f65" alt=""
Now I check I can ping the host I saw with Wireshark and I have a quick look at it's ports with Nmap.
ping -c 2 192.168.2.2
nmap 192.168.2.2
data:image/s3,"s3://crabby-images/02e16/02e16d259f83132773ea95a49be5da47fe1d05af" alt=""
Great, I have plenty here to play with, and on port 80 ...........
data:image/s3,"s3://crabby-images/87855/878552bc72543c8bacd0c3086c7c257a8094f336" alt=""
Okay obviously this was staged but hopefully it illustrates two things. VLANs can be abused and Yersinia rocks!!!!!!!!!