Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

4/7/2009
01:39 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Researchers To Unleash Backbone-Hacking Tools At Black Hat Europe

Tools automate attacks on Multiprotocol Label Switching (MPLS) and Ethernet carrier networks

A pair of German researchers at next week's Black Hat Europe will release tools that hack backbone technologies used by service providers in some enterprise network service offerings.

More specifically, the tools -- built by Enno Rey and Daniel Mende, both with German security firm ERNW -- automate attacks on Multiprotocol Layer Switching (MPLS) and Ethernet backbone technologies. They exploit similar, inherent security weaknesses in the two networking technologies -- namely, in how they forward traffic.

The lack of security in MPLS and Ethernet is well-known, but until now the exploitation of these network technologies has been only theoretically possible, Rey says. "Our release of the tools closes that gap of these attacks being only theoretical to being practically exploitable now," he says. "These technologies do not provide any security themselves, but just rely on the assumption that the underlying network is secure."

Network infrastructure security has been in the limelight lately, with researchers uncovering big vulnerabilities in the Domain Name System (DNS), the Border Gateway Protocol (BGP), TCP, and in Cisco routers.

MPLS VPNs originally were proprietary networks when they first hit the network scene. But the evolution of service provider networks to Internet-based services has put MPLS, as well as Ethernet, in the hot seat as possible hacking targets, Rey notes. MPLS networks used to have their "own set of switches and management infrastructures, and their own set of surrounding technologies," he says, "and the average attacker could not get his hands on that equipment."

To execute an MPLS or Ethernet carrier network hack, an attacker first must get into the network, either by hacking a router or a management tool. Then Rey and Mende's MPLS hacking tool could be used: It modifies the labels that are added to packets in an MPLS network and determines how those packets are forwarded. This lets an attacker silently redirect traffic to other sites, such as a malicious DNS server or a phony authentication server, Rey says. "The victim doesn't notice anything...and the attacker has both directions of traffic [in his control]," he says. "The whole VPN model of trust is violated."

The attack doesn't target a specific vulnerabilty -- just the way MPLS operates. The story is much the same for Ethernet. VLAN-tagging, for instance, helps carriers separate different customers' traffic across their backbones. "But there's no encryption and no additional security [with Ethernet]," Rey says. "It's just traffic separated by adding some more bits to the traffic, which brings us back to being able to modify those bits [with our hacking tool]."

Rey says enterprises that use these VPN services should be aware they are vulnerable. Perform risk analysis and encrypt your traffic, he says. "Just because it's called MPLS VPN [doesn't mean] you should [automatically] trust it," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.