Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

4/7/2009
01:39 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Researchers To Unleash Backbone-Hacking Tools At Black Hat Europe

Tools automate attacks on Multiprotocol Label Switching (MPLS) and Ethernet carrier networks

A pair of German researchers at next week's Black Hat Europe will release tools that hack backbone technologies used by service providers in some enterprise network service offerings.

More specifically, the tools -- built by Enno Rey and Daniel Mende, both with German security firm ERNW -- automate attacks on Multiprotocol Layer Switching (MPLS) and Ethernet backbone technologies. They exploit similar, inherent security weaknesses in the two networking technologies -- namely, in how they forward traffic.

The lack of security in MPLS and Ethernet is well-known, but until now the exploitation of these network technologies has been only theoretically possible, Rey says. "Our release of the tools closes that gap of these attacks being only theoretical to being practically exploitable now," he says. "These technologies do not provide any security themselves, but just rely on the assumption that the underlying network is secure."

Network infrastructure security has been in the limelight lately, with researchers uncovering big vulnerabilities in the Domain Name System (DNS), the Border Gateway Protocol (BGP), TCP, and in Cisco routers.

MPLS VPNs originally were proprietary networks when they first hit the network scene. But the evolution of service provider networks to Internet-based services has put MPLS, as well as Ethernet, in the hot seat as possible hacking targets, Rey notes. MPLS networks used to have their "own set of switches and management infrastructures, and their own set of surrounding technologies," he says, "and the average attacker could not get his hands on that equipment."

To execute an MPLS or Ethernet carrier network hack, an attacker first must get into the network, either by hacking a router or a management tool. Then Rey and Mende's MPLS hacking tool could be used: It modifies the labels that are added to packets in an MPLS network and determines how those packets are forwarded. This lets an attacker silently redirect traffic to other sites, such as a malicious DNS server or a phony authentication server, Rey says. "The victim doesn't notice anything...and the attacker has both directions of traffic [in his control]," he says. "The whole VPN model of trust is violated."

The attack doesn't target a specific vulnerabilty -- just the way MPLS operates. The story is much the same for Ethernet. VLAN-tagging, for instance, helps carriers separate different customers' traffic across their backbones. "But there's no encryption and no additional security [with Ethernet]," Rey says. "It's just traffic separated by adding some more bits to the traffic, which brings us back to being able to modify those bits [with our hacking tool]."

Rey says enterprises that use these VPN services should be aware they are vulnerable. Perform risk analysis and encrypt your traffic, he says. "Just because it's called MPLS VPN [doesn't mean] you should [automatically] trust it," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
MoviePass Leaves Credit Card Numbers, Personal Data Exposed Online
Kelly Sheridan, Staff Editor, Dark Reading,  8/21/2019
New FISMA Report Shows Progress, Gaps in Federal Cybersecurity
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/21/2019
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15516
PUBLISHED: 2019-08-23
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.
CVE-2019-15517
PUBLISHED: 2019-08-23
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
CVE-2019-15518
PUBLISHED: 2019-08-23
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
CVE-2019-15519
PUBLISHED: 2019-08-23
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
CVE-2019-15520
PUBLISHED: 2019-08-23
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.