Pentesting Layers 2 and 3

No ratings

Presented at BSidesPittsburgh 2014 by

Lower level network protocols have been around for decades and haven't changed much in that time. A number of tools to exploit weaknesses in those protocols have been released over the years, and those haven't changed much either. What has changed is the hardware. Routers used to be bulky, expensive, and proprietary. Now they are small, cheap, and open source. What better way is there to attack network gear than with another piece of network gear? This presentation will focus on layer 2 and layer 3 protocols, their weaknesses, and how to protect against exploitation. We'll revisit tools such as hping, Nemesis, Yersinia, Loki, and Scapy, and show how they can be used to attack vulnerable networks. Finally, we'll demonstrate the use of these tools on routers that run OpenWRT.