[00:00.000 --> 00:01.980] Both to people and to machines. [00:02.420 --> 00:05.440] Lying to machines involves lots of different techniques. [00:06.420 --> 00:13.100] Art poisoning is an effective way to intercept traffic, sniff, hijack, DOS network connections. [00:13.960 --> 00:21.840] It is a more effective way of hijacking connections because it allows you to see incoming and outgoing traffic and clear text. [00:22.500 --> 00:24.100] Now, H.D. Moore on bullet point 3, H.D. Moore on bullet point 3, H.D. Moore stated that the other 250 servers of the ISP were still vulnerable after they fixed Metasploit.com. [00:35.020 --> 00:37.060] So, two things. [00:37.240 --> 00:43.080] Either they didn't care or they said the other 250 servers aren't a target so we're not going to fix it. [00:43.440 --> 00:44.360] That's embarrassing. [00:44.620 --> 00:48.720] And if anybody knows that ISP provider, please let me know after. [00:48.720 --> 00:51.900] Because I never want to host my website with them. [00:56.320 --> 00:57.120] ARP attacks. [00:58.720 --> 01:01.380] Here we have a simple diagram of ARP spoofing. [01:01.860 --> 01:05.700] Corporate executives and managers think that this attack can't happen to them. [01:06.120 --> 01:11.380] Until they're on the front page of the Wall Street Journal or any other media outlet like Security Focus. [01:11.740 --> 01:13.280] And they say, oh, shoot. [01:13.980 --> 01:15.560] I'm out of a job, basically. [01:16.200 --> 01:25.440] So, here on the bottom, you see an easy way, by using Eater Cap, you could easily spoof server B. [01:25.940 --> 01:34.700] So, when server A sends the traffic, the attacker intercepts it with 2, then decides to forward it on to 3 and to 4 to server B. [01:36.100 --> 01:38.280] Now, ARP attack demo. [01:39.020 --> 01:40.900] First of its kind, human ARP attack. [01:41.340 --> 01:42.920] I need a volunteer to come up here. [01:44.500 --> 01:45.460] Raise your hand. [01:45.620 --> 01:47.060] Raise your hand in the crowd somewhere. [01:47.540 --> 01:47.980] Volunteer. [01:48.120 --> 01:48.920] You got one right here. [01:49.000 --> 01:49.380] No, no. [01:49.940 --> 01:50.620] Hold, hold. [01:51.020 --> 01:51.720] Any girls? [01:51.880 --> 01:52.260] Any women? [01:52.540 --> 01:52.780] Everybody. [01:53.260 --> 01:54.240] No, not you. [01:54.440 --> 01:54.860] Not you. [01:55.000 --> 01:55.840] Any women, please. [01:55.840 --> 01:57.100] I won't take it from you. [01:57.580 --> 01:57.800] No? [01:59.100 --> 01:59.720] Oh, man. [01:59.820 --> 02:00.040] All right. [02:00.400 --> 02:00.740] Come up. [02:00.840 --> 02:01.220] Come up. [02:01.980 --> 02:02.980] Come up right here. [02:05.000 --> 02:05.360] Yep. [02:05.680 --> 02:06.140] You're sitting right here. [02:06.140 --> 02:10.620] Now, of course, we were going to, you know, use laptops and try to do it through laptops. [02:10.820 --> 02:17.200] So, we were like, nah, let's switch it up, you know, because everybody pretty much knows how this goes and how easy it is. [02:17.220 --> 02:18.900] Yeah, it's really easy to do it. [02:19.040 --> 02:20.540] We wanted to do it in the human factors. [02:20.640 --> 02:20.900] All right. [02:21.040 --> 02:24.300] So, I'm going to be the spectator right now, and I'm going to walk you through the ARP spoofing. [02:24.960 --> 02:25.620] All right. [02:26.040 --> 02:27.740] So, Anthony, gentleman here. [02:28.500 --> 02:30.420] He is server A. [02:31.300 --> 02:31.780] Okay. [02:32.020 --> 02:32.840] My brother's the attacker. [02:32.900 --> 02:33.940] No, I want you to sit down. [02:34.100 --> 02:35.260] I want you to sit down. [02:35.840 --> 02:36.140] Go ahead. [02:36.240 --> 02:36.880] Anthony, sit down. [02:36.980 --> 02:37.380] Take a seat. [02:37.420 --> 02:38.480] I want my brother to stay up. [02:38.780 --> 02:39.920] So, he's server A. [02:40.520 --> 02:42.500] My brother's the attacker. [02:42.880 --> 02:44.020] And the gentleman, what's your name? [02:44.680 --> 02:45.160] Adrian. [02:45.440 --> 02:46.780] Adrian is server B. [02:47.460 --> 02:53.080] So, Anthony, server A sends a packet over to Adrian. [02:53.080 --> 03:00.520] He just intercepted the money, the attacker, and he's going to forward on and manipulate traffic. [03:00.900 --> 03:02.440] And he's not going to give him the $10. [03:02.740 --> 03:04.100] He's only going to give him $5. [03:04.640 --> 03:07.840] And again, he's using Ettercap to ARP spoof it. [03:07.840 --> 03:11.020] So, now, what you want to do is probably send a password. [03:11.580 --> 03:12.940] Hopefully, your ATM password. [03:13.920 --> 03:15.640] You want to send it over again. [03:16.360 --> 03:19.440] And he is going to do it again. [03:19.600 --> 03:21.240] And he's going to send it over. [03:22.000 --> 03:26.100] Now, the last one, what he's going to do is send more money. [03:27.500 --> 03:31.900] And what Kevin's going to do is, he's going to decide, that is kind of big. [03:31.940 --> 03:32.960] It got a lot of money in it. [03:33.060 --> 03:36.060] And he's going to dos that gentleman's connection. [03:36.060 --> 03:37.540] And he's not going to receive anything. [03:37.540 --> 03:40.200] But, give a round of applause for the gentleman. [03:40.580 --> 03:41.680] You get to keep it. [03:41.740 --> 03:42.780] You get to keep it, man. [03:44.720 --> 03:45.700] A little different. [03:45.760 --> 03:46.340] A little different. [03:46.460 --> 03:48.200] We don't want the just usual stuff. [03:48.520 --> 03:50.220] We're going to have another good one coming up. [03:51.380 --> 03:52.600] Back to the presentation. [03:53.220 --> 03:53.360] So, [03:56.680 --> 03:58.180] free money given away. [03:58.320 --> 03:59.620] You know the economy is hard now. [04:03.140 --> 04:05.020] So, ARP attack mitigation. [04:05.300 --> 04:06.660] So, how do we mitigate these risks? [04:06.760 --> 04:08.380] Non-changing ARP entries? [04:08.700 --> 04:09.980] Eh, I don't think so. [04:10.120 --> 04:11.060] Don't even waste your time. [04:11.480 --> 04:12.980] This is too time consuming. [04:12.980 --> 04:15.900] It's unmanageable on a big scale network. [04:16.120 --> 04:18.220] You would just kill all your resources. [04:18.940 --> 04:19.940] DHCP snooping. [04:20.100 --> 04:21.560] We covered this on the latest slide. [04:22.220 --> 04:30.700] ARP Watch is an open source software that monitors the computer network, the network for ARP activity. [04:31.360 --> 04:41.320] It generates a log of IP address, MAC address pairings, along with a timestamp when the pairing appeared on the network. [04:42.640 --> 04:44.760] So, I like it because it's free. [04:44.920 --> 04:45.500] Anything free? [04:45.680 --> 04:47.460] Hey, that's all me. [04:50.660 --> 04:53.340] MAC flooding and cam table overflow attacks. [04:53.980 --> 04:58.600] Switches maintain a list called cam tables, which is this yellow thing here. [05:00.720 --> 05:12.660] This enables it to send data to the physical port where the recipient computer is located. [05:12.660 --> 05:21.380] In a typical MAC flooding attack, the switch is flooded with packets, each containing different source MAC addresses. [05:22.280 --> 05:25.380] So, here, what you see is just a regular switch. [05:25.600 --> 05:27.160] It's operating normally. [05:27.440 --> 05:29.840] So, P1 sends data over to P2. [05:30.960 --> 05:32.700] Just regular conversation. [05:32.700 --> 05:33.820] And here we go. [05:34.020 --> 05:40.100] The attacker sends the MAC addresses onto the switch, and he decides to flood the cam table. [05:40.300 --> 05:42.800] And it starts broadcasting just like a hub. [05:45.700 --> 05:48.020] Now, this is where the attack gets good. [05:49.020 --> 05:50.800] I chose MAC-OF. [05:50.800 --> 05:51.660] Excuse me, excuse me. [05:51.720 --> 05:51.840] What? [05:51.840 --> 05:52.920] Oh, sorry. [05:53.380 --> 06:03.280] We chose MAC-OF to flood the switch with random MAC addresses, causing the switch to fail open in repeating mode. [06:03.860 --> 06:07.080] Hint, hint, this is when you want to have your sniffer running. [06:07.740 --> 06:08.340] Okay? [06:08.540 --> 06:09.820] So, you just blast the network. [06:10.000 --> 06:12.880] And here you see a screen backtrack. [06:12.880 --> 06:21.620] You can just load up backtrack and open up a prompt, type in MAC-OF, and it just starts generating packets on the wire, as you can see here. [06:22.180 --> 06:32.150] Now, the result of the last slide made the switch to bleed out, which is the fail open mode. [06:32.350 --> 06:40.850] All incoming packets were broadcasted throughout the switch, and you can see the username, password, and so on and so forth. [06:40.850 --> 06:43.450] And you can use Wireshark, whatever you prefer. [06:43.950 --> 06:45.910] I use K and A because I like it. [06:46.170 --> 06:51.670] And you can just catch more than just passwords, instant messaging, and so on and so forth. [06:55.460 --> 07:00.770] So, the mitigation for MAC flooding the cam tables is the same as the ARP attack. [07:01.440 --> 07:11.400] So, more advanced switches like Cisco and Oritel gives you the opportunity to set up protections against an attack with limiting the MAC addresses to that port. [07:12.600 --> 07:25.000] You can also set up a policy that if the port gets too many MAC addresses, the default is to shut it down, write a log, alert the admin with an email, and really it's up to the admin to find out. [07:33.180 --> 07:33.940] Alright. [07:35.040 --> 07:41.100] The DHCP starvation attack works by broadcasting DHCP requests to a spoof MAC address. [07:41.520 --> 07:45.480] This is easily achieved with attacks like Yesenia or Gobbler. [07:46.380 --> 07:54.200] If enough requests are sent, the network attacker can exhaust their address base available to the DHCP servers for a period of time. [07:56.180 --> 08:06.360] Now, here you see Yesenia broadcasting DHCP requests with spoof MAC addresses and trying to exhaust the DHCP IP pool. [08:06.620 --> 08:10.040] And here you just launch the attack and it starts running. [08:11.020 --> 08:13.740] And the thing is, my niece is eight years old. [08:13.900 --> 08:14.740] She's right over there. [08:14.960 --> 08:17.840] She could easily just do the same thing. [08:18.040 --> 08:20.260] Point and click and there's the attack. [08:20.560 --> 08:22.860] It's that easy and that fast. [08:23.480 --> 08:28.700] And it just generates a lot of all the traffic on there requesting IP addresses. [08:29.260 --> 08:32.900] And, oh yes, we do have a picture of that. [08:34.300 --> 08:36.120] Here you see the result of it. [08:37.190 --> 08:45.170] The Microsoft DHCP server, which we were running 2003, as well as I know it's vulnerable on 2000. [08:45.500 --> 08:49.080] I haven't tested 2008 yet, Windows Server 2008. [08:49.390 --> 08:52.430] So, I probably tested and posted on the blog. [08:53.410 --> 09:03.150] But, as you can see, the scary thing about this is that once this is down, once this has crashed, you could set up a rogue server. [09:03.530 --> 09:14.410] And you could, if a request comes in, you could give them an IP address, put the default gateway as your own IP, and make the traffic start directing through you. [09:14.810 --> 09:16.070] Which is kind of scary. [09:16.310 --> 09:18.770] And, as you see, it's 100% full. [09:19.120 --> 09:20.390] This is the event viewer. [09:20.790 --> 09:21.390] This is... [09:21.390 --> 09:27.480] What's bad about this is that even if you stop the attack, an admin has to go to the box and restart this service. [09:28.080 --> 09:32.240] Which, I think at 2 o'clock in the morning, the admin is not waking up and restarting it. [09:33.890 --> 09:34.360] Alright. [09:34.710 --> 09:35.770] We got another demo. [09:36.150 --> 09:37.890] And like I said, it's pointing clicks. [09:38.190 --> 09:43.150] So, what we do want to do is, we are the DHCP servers. [09:43.480 --> 09:43.770] Right? [09:44.290 --> 09:46.050] I think we should stand up for this. [09:46.290 --> 09:48.100] This money is the IP addresses. [09:48.360 --> 09:49.480] Who wants IP addresses? [09:49.480 --> 09:50.960] Who wants IP addresses? [09:51.580 --> 09:58.890] So, if you run the attack of Yesenia that we just showed you, and you run it kind of easy, like point and click. [09:59.910 --> 10:00.810] So, no, no. [10:01.030 --> 10:02.170] Nobody wants to stand up. [10:02.270 --> 10:03.080] So, what are we going to do? [10:03.310 --> 10:03.890] I don't know. [10:03.960 --> 10:04.340] I don't know. [10:04.430 --> 10:04.830] Let's do it. [10:04.860 --> 10:05.390] One, two, three. [10:06.100 --> 10:08.980] We just going to throw it into the crowd and give it out. [10:10.500 --> 10:12.980] And, as you can see, most of the people picked it up. [10:13.080 --> 10:14.430] We didn't throw it too far enough. [10:14.430 --> 10:16.120] Just having fun. [10:16.270 --> 10:16.410] Yeah. [10:16.810 --> 10:16.910] Yeah. [10:18.950 --> 10:21.620] As you can see, there aren't any more dollars. [10:23.410 --> 10:25.600] But, there's a little catch to this. [10:25.950 --> 10:30.000] As you see my brother, walking off stage. [10:31.270 --> 10:31.410] Oh. [10:32.190 --> 10:33.720] No, you got it right there. [10:36.250 --> 10:37.650] You got it right there. [10:38.510 --> 10:40.890] Alright, as you see my brother walking off stage. [10:41.960 --> 10:49.980] He is the rogue server giving the IP addresses out because all the IP addresses are taken. [10:50.240 --> 10:51.310] So, he's the rogue server. [10:51.450 --> 10:52.120] He's going over there. [10:52.210 --> 10:54.100] Let him give out IP addresses. [10:55.030 --> 10:56.910] You know, gas is $4. [10:57.390 --> 11:01.980] You know, I'm just trying to help the economy out and put money right back into the economy. [11:02.390 --> 11:04.800] You know, that's George Bush's money, by the way. [11:04.910 --> 11:06.120] He gave it to me in April. [11:06.120 --> 11:07.000] Yeah. [11:09.980 --> 11:10.820] Yeah. [11:11.500 --> 11:11.880] Yeah. [11:14.520 --> 11:17.180] Alright, DHCP snooping. [11:17.700 --> 11:19.640] Let me swing it over. [11:20.600 --> 11:23.980] DHCP snooping restricts DHCP requests. [11:24.260 --> 11:31.480] But again, guys, if you can have the money, tell your IT manager to upgrade his switches. [11:31.480 --> 11:36.280] And guys, if you consult, this is a great way to make money. [11:36.940 --> 11:39.240] You could go to your clients and blast them. [11:39.800 --> 11:41.020] Blast them and say, hey, look. [11:41.360 --> 11:41.640] Look. [11:42.300 --> 11:44.520] I'm just saying, you should buy the switches off me. [11:44.780 --> 11:45.360] Third party. [11:46.400 --> 11:47.800] And you put your money on there. [11:47.820 --> 11:49.300] It's a great way to make money as well. [11:49.620 --> 11:55.600] And it's vulnerable because a lot of small companies, mid-sized companies still have this old equipment. [11:55.600 --> 12:00.640] And you could easily make a pretty good chunk for you consultants out there like myself. [12:02.940 --> 12:04.520] So, where am I? [12:06.080 --> 12:06.540] Oh. [12:08.500 --> 12:09.180] Yep. [12:12.180 --> 12:14.420] What the heck is those clocks there? [12:15.520 --> 12:16.360] Don't know. [12:17.040 --> 12:20.820] The most obvious risks associated with CDP is information leakage. [12:22.660 --> 12:24.760] CDP is Cisco Discovery Protocol. [12:25.280 --> 12:26.720] By default, they're turned on. [12:27.840 --> 12:32.440] The CDP communicates amongst one another via clear text and unauthenticated. [12:32.680 --> 12:42.780] By claiming to be a phone, an attacker can reserve some electrical power, denying other valid devices from receiving power from the switch. [12:42.880 --> 12:43.480] Which is sad. [12:43.680 --> 12:47.600] Because then, your colleagues ain't gonna have any phone. [12:47.600 --> 12:49.700] And they're gonna be upset at you. [12:50.780 --> 12:57.760] Another CDP attack that is still relevant is a vulnerability in Cisco IOS 12.1 and 12.2. [12:58.040 --> 13:00.040] Which handles CDP announcements. [13:00.560 --> 13:08.460] You can receive all the device available memory by sending large amounts of CDP neighbor announcements to the device. [13:09.820 --> 13:18.940] And as you can see, we attacked Cisco IOS version 12.0, which was vulnerable to the Denala service. [13:19.260 --> 13:25.220] While residing on the same network segment as the targeted device, we flooded the switch. [13:25.220 --> 13:27.860] As you can see here, we were on port 2, switched on port 10. [13:27.860 --> 13:29.260] We ran... [13:29.260 --> 13:29.540] We ran... [13:29.540 --> 13:33.580] Yesenia has the capable attack, CDP attack as well. [13:33.780 --> 13:34.700] And as you see... [13:34.700 --> 13:36.000] As you see memory... [13:36.000 --> 13:37.380] Where are we at here? [13:37.380 --> 13:38.300] I wanna point to it. [13:38.500 --> 13:39.780] Memory allocation here. [13:40.400 --> 13:42.340] So we did that as well. [13:44.580 --> 13:47.360] And, you know, not much you could do. [13:47.440 --> 13:53.060] And it could be said about CDP, you know, countermeasures, except turn the shit off. [13:53.460 --> 13:57.160] The question arises is why it's turned on in the first place. [13:57.520 --> 14:00.060] You know, IP phones right now is very popular. [14:00.540 --> 14:03.560] But CDP is... [14:03.560 --> 14:04.340] It's... [14:04.340 --> 14:06.040] You shouldn't have it on at all. [14:06.560 --> 14:07.100] You know? [14:07.540 --> 14:08.100] At all. [14:08.840 --> 14:09.320] So... [14:09.320 --> 14:14.560] If anyone out there knows why CDP is indispensable... [14:14.560 --> 14:15.420] After the... [14:15.420 --> 14:16.020] What? [14:18.920 --> 14:19.560] Yeah, yeah. [14:19.680 --> 14:19.920] I know. [14:20.060 --> 14:20.480] I know that. [14:20.840 --> 14:21.680] That's what I'm saying. [14:21.800 --> 14:24.280] IP phones is popular, but... [14:25.140 --> 14:27.700] Shouldn't be that popular that I blast that. [14:28.000 --> 14:28.060] You know? [14:28.180 --> 14:32.380] Try having 200 WAN links on a router and we don't know what's going on inside. [14:34.320 --> 14:34.980] All right. [14:35.260 --> 14:35.720] So... [14:36.320 --> 14:37.060] Anthony, you wanna... [14:37.060 --> 14:37.960] You wanna go? [14:39.200 --> 14:39.980] Thank you, Marco. [14:40.780 --> 14:41.700] Can you guys hear me in the back? [14:42.500 --> 14:42.900] Yeah. [14:43.300 --> 14:43.620] All right. [14:47.120 --> 14:47.700] Excuse me. [14:48.020 --> 14:48.460] Keep in mind. [14:49.700 --> 14:50.580] Note's in over the blue. [14:56.740 --> 14:57.800] Spanning tree protocol. [15:02.980 --> 15:06.360] That allows you to build a loop-free topology on your network. [15:06.540 --> 15:07.580] It kind of looks like a tree. [15:08.220 --> 15:08.680] Beg your pardon? [15:08.960 --> 15:09.500] Speak up. [15:09.660 --> 15:10.240] Speak up. [15:10.340 --> 15:10.520] Okay. [15:10.520 --> 15:10.540] Yeah. [15:11.460 --> 15:18.980] The spanning tree protocol allows you to set up a loop-free topology on your network that is analogous or looks like a tree. [15:21.360 --> 15:23.180] So, just to kind of give it a brief look. [15:23.320 --> 15:26.460] How a spanning tree protocol attack looks is... [15:26.460 --> 15:27.140] What the hell? [15:27.520 --> 15:29.380] It allows you to... [15:29.380 --> 15:32.060] An attacker to spoof the root bridge of the topology. [15:32.840 --> 15:34.320] So, the root bridge is... [15:34.320 --> 15:43.020] When you have BPDUs or bridge protocol data units, they broadcast out to see who has the lowest ID. [15:43.520 --> 15:45.940] The one that has the lowest ID is the root bridge. [15:46.660 --> 15:50.660] So, all these attacks are really just straight from the Yersinia man page. [15:52.120 --> 15:53.820] I'll just go over them pretty quickly. [15:54.040 --> 15:55.940] So, you can send raw configuration BPDUs. [15:56.960 --> 15:58.040] I'll skip over some. [15:58.340 --> 16:01.340] You can claim the root role, which is a very dangerous thing. [16:01.600 --> 16:05.180] Or claim another role as far as the topology is concerned. [16:05.760 --> 16:09.960] Or, one of the more damaging attacks is a man in the middle attack that can take place. [16:10.380 --> 16:13.480] If you claim root roles in a dual home type of a situation. [16:13.780 --> 16:17.280] Either when you have access to two switches to plug into. [16:17.600 --> 16:20.420] Or, one switch on a wireless network. [16:20.520 --> 16:21.980] Another switch on a wireless network. [16:22.160 --> 16:27.420] And you have two wireless cards to effectively perform the same type of attack in a wireless type of a scenario. [16:35.880 --> 16:43.460] In this example, you see STP sending configuration BPDUs in a denial of service type of a role using Yersinia. [16:45.240 --> 16:46.340] So, it's very simple. [16:46.500 --> 16:47.320] You just can... [16:47.320 --> 16:47.440] Whoops. [16:47.580 --> 16:48.080] Sorry about that. [16:54.880 --> 16:55.640] Going backwards? [16:57.140 --> 16:57.940] I'm confused. [16:58.100 --> 16:59.720] We ran out of money, so... [17:06.810 --> 17:13.010] So, you have your radio button where you can send configuration BPDUs in a denial of service scenario. [17:22.710 --> 17:25.170] So, we're going to talk about some mitigation here. [17:25.370 --> 17:31.950] So, the spanning tree functions should be disabled on all user interfaces or all user ports as pertains to a switch. [17:32.810 --> 17:36.030] You definitely want to enable root guard on Cisco equipment. [17:36.030 --> 17:41.930] Or, if it's not a Cisco type of environment, whatever pertains to that type of equipment that you're using. [17:44.990 --> 17:54.110] The example here shows a Cisco enable prompt, the exact commands that you'd want to type in to enable that type of protection. [18:00.400 --> 18:01.660] Multicast brute force attacks. [18:01.920 --> 18:07.260] I'll just gloss over these pretty quick because it looks like we're shortening up on time here. [18:07.260 --> 18:09.220] I know we have a lot of slides to be able to run through for you. [18:11.100 --> 18:14.040] So, a multicast is basically in a class D. [18:15.140 --> 18:16.400] I don't think it is. [18:18.240 --> 18:18.640] Okay. [18:19.900 --> 18:20.980] I think it is. [18:21.120 --> 18:21.720] Alright, there we go. [18:21.980 --> 18:22.800] Sorry about that. [18:26.140 --> 18:34.720] Multicast allows you to do one-to-many or many-to-many using a single packet that gets replicated throughout the network by your gear to be able to save on traffic. [18:35.520 --> 18:39.020] So, what an attacker would do is spoof that in a rapid succession. [18:39.660 --> 18:41.320] A series of multicast frames. [18:42.820 --> 18:45.680] Frames when they leak into other VLANs if they're not set up properly. [18:51.700 --> 18:57.440] So, the mitigation that you can use for these types of attacks are buy more capable switches. [18:57.780 --> 19:00.260] You could use the money that we put out into the crowd to do that. [19:03.930 --> 19:08.870] Or ensure that your layer 2 multicast packets are constrained within the ingress VLANs. [19:08.870 --> 19:11.590] So, no packets should be able to leak across VLANs. [19:11.670 --> 19:15.450] You can check that with TCP dump, Wireshark, NetDude. [19:15.730 --> 19:16.570] Pick your poison. [19:20.520 --> 19:22.180] The VLAN trunking protocol. [19:24.980 --> 19:29.420] So, this has the ability to add and remove dynamically VLANs from the network. [19:31.180 --> 19:35.300] So, all client VTP switches erase their VLANs once receiving the messages. [19:36.560 --> 19:44.420] Types of attacks you can do are sending VTP packets, delete all VTP VLANs, delete one VLAN, or add one VLAN. [19:45.180 --> 19:51.100] That's all run through a VTP server on the network which should have its own VLAN and dedicated port. [19:54.870 --> 19:57.090] How do you mitigate against that? [19:58.750 --> 20:03.530] Well, make sure that the VTP traffic is definitely not going to user ports. [20:03.670 --> 20:06.790] Only to the port that the server has been allocated. [20:15.230 --> 20:18.270] Make sure, if you're a consultant, you don't want to do those attacks. [20:18.530 --> 20:21.410] Because you won't... you'll just be like, no, go home. [20:22.170 --> 20:26.170] As a matter of fact, we'll probably press charges because you're going to be doing a lot of bad stuff. [20:26.430 --> 20:28.850] So, I just wanted you to be aware of that. [20:30.610 --> 20:31.510] Back to you, Kev. [20:31.610 --> 20:31.910] All right. [20:33.210 --> 20:40.550] So, the next three attacks that I'm going to speak about is private VLAN, VLAN hopping, and 802.1Q double encapsulation. [20:42.270 --> 20:46.230] Of course, we all know that private VLANs were meant to isolate traffic on a switch. [20:46.430 --> 20:53.610] And if they went from one switch to another, they would have to pass through a router that would be done on layer 3. [20:54.430 --> 20:59.790] So, a couple of months ago, Anthony right here introduced me to this program called Scapy. [20:59.950 --> 21:06.650] And once I learned that program, I was stuck in my seat for three days without moving, just wanting to learn all about this program. [21:06.650 --> 21:08.610] It's an incredible program. [21:09.010 --> 21:09.570] It's an incredible program. [21:09.570 --> 21:12.370] You could do anything you want to pack it. [21:12.490 --> 21:15.810] And when I say anything, anything you want to pack it. [21:19.770 --> 21:26.970] So, about the same time I acquired a client and I was going through the Internet and I came across this picture. [21:27.310 --> 21:30.470] And this picture sort of looked like what my client had set up. [21:30.690 --> 21:32.870] They have a POP down in Lower Manhattan. [21:33.130 --> 21:38.190] Their main office was in Midtown and satellite offices throughout the United States. [21:38.970 --> 21:50.110] So, these satellite offices would log into this POP, which would then transfer the information through the different VLANs going to the headquarters office in Midtown. [21:50.890 --> 21:52.950] And one of them was HR. [21:52.950 --> 21:57.990] The other one was DMZ and other departments within their company. [21:58.850 --> 22:02.290] So, I decided to put a sniffer right here. [22:03.290 --> 22:10.670] And the traffic that I started receiving, I used regular Wireshark, nothing crazy or anything like that. [22:10.670 --> 22:14.590] I started picking up 802.1q packets. [22:14.690 --> 22:23.050] And in Wireshark, if you click on the 802 portion of it, it shows you what VLAN number that information is running on. [22:23.050 --> 22:27.990] So, of course, because Scapy is such a wonderful packet generating program. [22:28.370 --> 22:37.310] I started gathering more information about HR and gathering information about their DMZ and their security department and so on and so forth. [22:38.110 --> 22:46.490] I'll get back to this picture a little bit later because some stuff that I want to speak about before showing you this other picture and what I did with this VLAN. [22:46.610 --> 22:47.790] But please remember this picture. [22:50.050 --> 22:55.690] So, the first thing is, back at this switch, they had a router here that I left out. [22:55.890 --> 23:05.950] But back at this router level, you should make sure that you configure your ingress filters for VLAN so this stuff that I'm doing won't happen. [23:06.710 --> 23:13.170] And that's a brief command that you could set for your access list on the router. [23:15.450 --> 23:19.930] So, now going on to the second portion of this is the VLAN hopping. [23:20.290 --> 23:28.910] So, once I acquired this information off that switch that I was sniffing out, I started using Scapy and spoofed that switch. [23:29.490 --> 23:37.570] And with Scapy, you can actually go and fool the switch into thinking it was itself or however you wanted to do it. [23:40.090 --> 23:49.820] So, this switch right here is that piece right there. [23:50.640 --> 23:59.200] So, once I was able to gather all the information about these different VLANs, and of course the VLAN IDs are changed just in case if you try to go back to the old client. [24:00.740 --> 24:10.360] But I set up my laptop on this, put it on the switch, and once I started acquiring that information, I started getting HR information that I shouldn't have. [24:11.580 --> 24:20.340] Stuff about their DMZ that I shouldn't have and definitely a lot of information on their marketing and accounting with their other VLANs. [24:20.340 --> 24:26.980] So, I use Scapy to go in full and change the packet of the 802.1Q. [24:27.100 --> 24:28.780] I got another slide on that in a second. [24:29.060 --> 24:34.820] But just to try to... the next piece I want to talk about is how to prevent VLAN hopping from happening. [24:36.240 --> 24:38.360] Of course, disable auto-trunking. [24:38.580 --> 24:42.660] I don't know why people leave auto-trunking enabled unless they're really lazy. [24:42.660 --> 24:46.420] The next one is ports that are not being used. [24:46.660 --> 24:47.420] Shut them down. [24:49.460 --> 24:55.280] Another thing... another one is explicitly configure your trunk ports on a switch. [24:55.560 --> 25:03.040] If you have auto-trunking enabled, you can totally switch the information onto a port that isn't disabled. [25:04.240 --> 25:06.620] And last but not least, don't use VLAN 1. [25:09.410 --> 25:14.550] So, this is the last piece of the three pieces that I was speaking about. [25:14.810 --> 25:17.330] And to me, this is the most important piece. [25:18.010 --> 25:24.570] Because if you double encapsulate a packet, you could easily trick some of the switches. [25:24.970 --> 25:29.370] And do a lot of people in here know about VLANs and things like that? [25:29.390 --> 25:31.210] Or just for the first time? [25:31.490 --> 25:32.470] Of course, they're in IT. [25:33.890 --> 25:35.770] A lot of IT people don't. [25:37.390 --> 25:40.850] But inside a packet, there's a VLAN ID number. [25:41.190 --> 25:46.850] And that extends the packet a little bit more out to have that information inside there. [25:47.250 --> 25:55.710] The next thing is when it jumps from one switch to another, those packets will have a 802.1Q tag. [25:55.870 --> 25:59.210] And that tag will also have the VLAN ID information. [25:59.210 --> 26:03.850] And while sniffing out on Wireshark, I was able to acquire it. [26:03.870 --> 26:06.710] And that's how I was able to go into these other VLANs. [26:09.370 --> 26:12.970] This is the interesting part that I wanted to show people. [26:12.970 --> 26:16.330] So this was me right here being the attacker. [26:16.930 --> 26:18.630] And of course, I used Scapi. [26:19.290 --> 26:23.570] And what I did was I took this packet right here. [26:23.730 --> 26:28.150] And in Scapi, I just created two double encapsulation packets. [26:28.790 --> 26:36.670] So this number seven right here is one VLAN ID, which was a bogus one that I just used. [26:36.670 --> 26:39.350] And this was VLAN number 27. [26:40.910 --> 26:47.670] So using Scapi, I took this 802.1Q tag, which was the first one. [26:47.770 --> 26:48.730] And I made that one seven. [26:49.190 --> 26:50.590] And this one 27. [26:51.230 --> 26:53.410] So I send information to this switch. [26:53.770 --> 26:57.690] The switch automatically strips off the 802.1Q. [26:57.930 --> 27:00.870] But because there's two of them, it's not going to strip both of them off. [27:00.870 --> 27:03.250] It's only going to strip one off, leaving the other one there. [27:04.810 --> 27:07.850] And I wanted to go and attack this one. [27:08.110 --> 27:10.890] So once it stripped it off, it still had the tag. [27:11.070 --> 27:12.390] It sent it off to the other switch. [27:12.910 --> 27:17.290] And switch two assumed that switch one put that one in there. [27:17.610 --> 27:20.590] By then, it just passed the traffic. [27:20.610 --> 27:25.750] And I was able to go and target that machine and do what I had to do after that. [27:27.490 --> 27:39.530] So in order to ensure that this doesn't happen, of course, I was just informed a couple of days ago that there's a new iOS that stops double encapsulation packets. [27:39.850 --> 27:42.530] If anybody has information on that, please give it to me. [27:42.630 --> 27:44.690] I want to test some stuff out against that. [27:44.690 --> 27:52.330] The next thing is don't use native VLANs to ensure assigning onto ports. [27:53.470 --> 28:00.290] And last but not least, force all packets that go over the chunk port to have at least a tag. [28:00.450 --> 28:05.530] And like I said, there's an iOS, I believe, that stops the double encapsulation. [28:05.530 --> 28:06.550] But I'm not too sure. [28:06.630 --> 28:09.110] And I want to do more research on that one. [28:11.230 --> 28:15.730] And last but not least, VMPS. [28:16.490 --> 28:20.870] Now, does anybody in here use VMPS at their office? [28:21.970 --> 28:22.530] No. [28:22.830 --> 28:23.130] Okay. [28:23.490 --> 28:24.510] That's a good thing. [28:25.190 --> 28:27.310] This can really, really... [28:27.310 --> 28:33.210] They say this is supposed to be safe and everything, but this can really damage a network from within. [28:33.210 --> 28:39.490] And the reason why is most important is a lot of this information being passed through the switch is clear text. [28:39.730 --> 28:45.210] So if it isn't encrypted or anything like that, and it's clear text, God knows what can happen after that. [28:46.070 --> 28:49.310] And also, it's sent over UDP. [28:49.310 --> 29:02.810] So if you have, like, some TFTP client, and the information new, someone new comes in with a laptop and they get access to go on to this VLAN, it automatically... [29:02.810 --> 29:12.630] If they have their TFTP server on the switch, it sends that information, updates the VMPS policy, and automatically puts that person in. [29:12.630 --> 29:18.050] So if I was an attacker and I'd just go to office and go right ahead and try to log in. [29:18.230 --> 29:23.650] If this VMTP, if they don't have it set up correctly, it'll issue me on and I'll be able to get on to a VLAN. [29:23.730 --> 29:31.490] Of course, most companies try to set it up and aggregate it that new people coming into the company or anything have to go through certain things. [29:31.490 --> 29:40.850] But as for what I did to this client, they didn't, and because of a lot of misconfigurations, I was able to go and attack this. [29:45.720 --> 29:47.660] There's a mistake up here on this. [29:47.780 --> 29:49.080] This is supposed to be VQP. [29:51.360 --> 29:52.280] Sorry about that, Kevin. [29:52.520 --> 29:53.600] It's okay, thank you. [29:53.700 --> 29:54.840] I'll catch you afterwards. [29:55.600 --> 29:58.360] By the way, we're brothers for real, so... [30:00.300 --> 30:07.440] The first thing is, don't transmit VQP information unless it's going to be on an outer bandwidth. [30:07.820 --> 30:16.280] And the second thing is, if you are going to implement VMPS, then you probably have the resources and capabilities to go and monitor this stuff. [30:16.500 --> 30:21.520] So that's pretty much the only thing for VMPS. [30:21.760 --> 30:25.900] And if you don't have to use it, then don't use it at all. [30:28.140 --> 30:37.120] And to wrap it up, the final thing is, these are a couple of solutions in order to prevent all these attacks from happening. [30:37.120 --> 30:42.640] And one of my most important and favorite things is this right here. [30:42.900 --> 30:52.260] Select using SNMP as a threat for commuter string and treat it like a root password. [30:52.620 --> 30:55.840] A lot of people don't treat this like that. [30:56.040 --> 31:04.560] And so much information can be passed through here that can make your network very, very open and exploitable. [31:04.560 --> 31:09.880] So it's quite important that you treat those community strings like root passwords. [31:12.020 --> 31:23.520] And I don't want to go off and reading off on a tangent like that, but these are pretty much all the mitigating things to prevent these from happening. [31:24.540 --> 31:27.260] This is open up for questions and... [31:27.260 --> 31:27.260] Hold on. [31:27.300 --> 31:28.320] Go to the next slide one sec. [31:29.520 --> 31:29.780] Ah. [31:30.400 --> 31:30.820] Oh, you... [31:30.820 --> 31:31.340] This is our website. [31:31.340 --> 31:31.920] Wait, wait, wait. [31:32.000 --> 31:32.360] Hold on. [31:32.540 --> 31:35.380] You can put that one in, but you can't change my changes, right? [31:35.640 --> 31:36.900] I got you on that. [31:37.700 --> 31:38.240] All right. [31:38.400 --> 31:38.480] All right. [31:38.480 --> 31:40.420] This is our website, guys, and emails. [31:40.680 --> 31:42.780] You can definitely send us an email. [31:43.060 --> 31:44.380] Definitely answer some questions. [31:44.540 --> 31:52.120] As well as, I know if you go to my site, our site over here, MAF, I'll probably have it up. [31:52.200 --> 31:53.200] As well as K&T. [31:53.260 --> 31:54.080] You putting that up too? [31:54.120 --> 31:54.340] Yeah. [31:54.520 --> 31:55.520] I'll definitely have it. [31:55.640 --> 31:58.760] My website is the K&T International Consulted. [31:59.160 --> 32:03.700] Email address by, hopefully by tonight or tomorrow night, I'll have more information up there posted. [32:03.700 --> 32:04.240] And... [32:04.240 --> 32:05.760] So you can download the presentations. [32:06.140 --> 32:08.560] I also have like a 97-page white paper. [32:09.240 --> 32:11.020] I didn't want to put that up. [32:11.020 --> 32:11.260] Hold on. [32:11.340 --> 32:12.320] It'll be up on the site. [32:12.440 --> 32:13.660] You can download it over there too. [32:13.740 --> 32:14.780] I made another mistake. [32:15.240 --> 32:17.060] I forgot to put his website. [32:17.180 --> 32:17.580] What is it? [32:18.020 --> 32:18.740] IronGuard.net. [32:18.820 --> 32:19.300] That's really nice. [32:19.620 --> 32:19.980] IronGuard... [32:19.980 --> 32:20.560] It's up there? [32:20.880 --> 32:21.660] IronGuard.net. [32:22.640 --> 32:23.840] I'm sorry about that, Anthony. [32:25.120 --> 32:26.700] But that'll be posted up tonight. [32:26.860 --> 32:31.980] So you guys can download the presentation tonight around maybe 10 o'clock if you guys want to have it. [32:31.980 --> 32:40.800] And one thing I wanted to add on this, definitely go to your bosses or go to the people that make decisions and show them this presentation. [32:41.020 --> 32:42.080] Because it makes a difference. [32:42.420 --> 32:45.880] It gives you a little leverage that you can say, hey, look, you're vulnerable. [32:47.080 --> 32:48.560] Does anybody have any questions? [32:50.340 --> 32:50.780] No. [32:51.060 --> 32:51.380] No. [32:51.500 --> 32:53.560] You do not get any questions at all. [32:53.920 --> 32:54.000] No. [32:54.140 --> 32:54.760] Not you. [32:55.040 --> 32:57.220] You come to my house and ask me questions. [32:57.420 --> 32:58.300] Don't ask them here. [32:59.700 --> 33:00.640] Where's the cables? [33:12.140 --> 33:12.640] That... [33:13.860 --> 33:14.360] Semi... [33:14.360 --> 33:15.300] You want to ask them? [33:15.300 --> 33:22.160] Well, in order to start the piece of the attack, yeah, you have to be able to go onto the switch. [33:22.360 --> 33:25.980] But there is ways of passing firewalls. [33:25.980 --> 33:27.740] Scapy, Scapy, Scapy. [33:27.740 --> 33:31.420] With Scapy, you could pin any firewall you want. [33:31.660 --> 33:31.980] Anyone. [33:32.380 --> 33:33.900] It doesn't matter what it is. [33:34.260 --> 33:34.820] But depending... [33:34.820 --> 33:36.700] But once you bypass all that, yes. [33:39.670 --> 33:40.070] No. [33:40.410 --> 33:50.570] There's something that you're a cable provider and you're looking at, you know, everyone's aren't going to hold it. [33:50.870 --> 33:51.730] Where do you live at? [33:53.170 --> 33:53.690] Yeah, like he's going to answer that. [33:53.690 --> 33:54.590] Just a short note. [33:54.930 --> 33:56.210] And I'll tell you where I live at. [33:56.830 --> 33:58.370] You bring up something valid. [33:58.510 --> 33:59.470] That's why I bring this up. [33:59.570 --> 34:00.530] Time Warner Cable. [34:00.650 --> 34:01.510] Oh, okay. [34:01.590 --> 34:03.590] I live in the Bronx and I have Cablevision. [34:04.870 --> 34:06.550] Cablevision does the same exact thing. [34:06.650 --> 34:07.950] Did everybody get to hear what he said? [34:07.950 --> 34:08.510] No. [34:08.710 --> 34:09.210] Here you go. [34:09.330 --> 34:09.610] Here you go. [34:09.770 --> 34:10.410] Give him a mic. [34:10.850 --> 34:12.430] Let everybody know the question again. [34:15.010 --> 34:17.790] So I live in lower New York, southeastern New York. [34:17.910 --> 34:19.210] So I have Time Warner Cable. [34:19.630 --> 34:30.170] So you ever wonder that if you have your computer connected to a Linksys router or whatever router it is and it goes back to the cable, you see the cable modem light just lighting up all the time. [34:30.970 --> 34:32.490] And that's all that ARP traffic. [34:32.650 --> 34:36.730] Everyone looking for IP addresses or the routers and switches saying, who got this IP address? [34:36.730 --> 34:37.910] Who got this IP address? [34:38.550 --> 34:43.210] And maybe my neighbor annoyed me because they had a party late the other night, but I know they used the Internet. [34:43.790 --> 34:45.450] There's my man in the middle attack. [34:45.670 --> 34:46.990] So there you go. [34:47.370 --> 34:47.730] Okay. [34:48.810 --> 34:53.270] So once again, I live in the Bronx and what he brought up was a total valid point. [34:53.470 --> 34:57.810] So when I first got my cable into the house, I was like, oh, yes, I got three megs down. [34:57.990 --> 34:58.810] This is awesome. [34:58.810 --> 35:04.250] You know, and all of a sudden my three megs went to like 1.5 and I'm wondering why. [35:04.530 --> 35:05.070] You know? [35:05.350 --> 35:13.230] And it's because everybody on my block around the same time between like six o'clock and nine o'clock at night, everybody loves to jump on the Internet. [35:13.430 --> 35:18.310] So we only have one pipeline on the block that shoots out to everybody's house individually. [35:18.310 --> 35:25.510] And if all that traffic keeps going up and down a pipe like that, we can pretty much assume what's going to happen next. [35:25.690 --> 35:30.670] Especially when I have annoying neighbors, so they don't get access to Internet that much sometimes. [35:31.030 --> 35:31.350] Yeah. [35:32.230 --> 35:34.670] But it could totally, totally happen. [35:34.690 --> 35:43.610] So we just decided let's get our own business line into the house and we'll have our three megs down for torrents or something and use our regular bandwidth for all our other things. [35:43.830 --> 35:43.950] You know? [35:44.190 --> 35:45.390] The good torrents. [35:45.610 --> 35:46.030] Right? [35:47.330 --> 35:47.810] Yeah. [35:48.290 --> 35:49.390] Any other questions? [35:49.690 --> 35:49.870] Yes? [35:58.780 --> 36:09.840] If I was an attacker and I wanted to go and hit VLANs and didn't have any information about any VLANs that were on a network, which one do you think I'm going to try first? [36:12.960 --> 36:14.380] I'm going to start off with one. [36:16.850 --> 36:18.250] It's the best way to start. [36:18.250 --> 36:22.850] And if you have VLANs, like say VLAN one on a port, right? [36:23.050 --> 36:26.980] And you don't have it natively to the switch itself. [36:28.420 --> 36:38.000] If you have it on that one port and it's VLAN one, you know, and there's delicate information or any servers and stuff like that, I'm going to be able to compromise that right away. [36:38.000 --> 36:47.210] The point of, to me, the point of putting these VLANs is to try to hide and isolate the traffic on there so no one else can get access to it. [36:47.350 --> 36:50.380] So you want to treat that VLAN ID like gold. [36:51.110 --> 36:53.690] Oh, gold's kind of down, so let's go with platinum. [36:55.040 --> 36:56.500] Or oil at that. [36:58.690 --> 37:05.330] But, so, like I said, if I went on to like that client, the first thing I did was hit VLAN one. [37:05.460 --> 37:07.050] I know VLAN one has to be out. [37:07.190 --> 37:12.570] Unless they're really good, the majority of times, you know, a lot of people wind up not choosing VLAN one. [37:12.750 --> 37:15.420] And also because Cisco says so. [37:18.130 --> 37:19.630] Yeah, go right ahead. [37:19.630 --> 37:20.210] VLAN. [37:22.350 --> 37:23.960] Oh, we got a Cisco shirt. [37:24.440 --> 37:25.400] Oh, watch. [37:28.310 --> 37:31.930] Yeah, ADA 2.1Q uses something called native VLAN. [37:32.190 --> 37:38.270] And unlike all the other VLANs, the native VLAN has no tag. [37:41.250 --> 37:51.990] So, if there is a tag, right, so just like in your example where you had the two tags, right, if there is a tag, the second tag just looks like data to the first switch and is ignored by the switch. [37:52.210 --> 37:57.830] But if there's no tag, then the native VLAN is normally used. [37:57.990 --> 38:17.150] But if you have spoofed a tag and then sent it onto the native VLAN, right, so you're sending it over a connection that's not supposed to have a tag, but you've added one of your own so that the data was supposed to go over the native VLAN, but your spoofed tag causes it to go over the VLAN of your choice instead. [38:17.510 --> 38:21.770] So that's a way of leaking over to another VLAN. [38:23.470 --> 38:25.510] And also on what switch would that be? [38:25.630 --> 38:28.230] Because the higher switches prevent things like that from happening. [38:28.450 --> 38:32.430] And the default VLAN to use for the native VLAN is VLAN number one. [38:33.710 --> 38:39.750] Well, there you go, a Cisco guy saying use VLAN number one, but I guarantee you that's not a good thing to do. [38:41.030 --> 38:43.230] You said a default, not recommended. [38:44.250 --> 38:47.190] There's a default password too, but they suggest changing them. [38:49.970 --> 38:50.510] All right. [38:50.810 --> 38:51.530] Any other questions? [38:53.090 --> 38:54.530] You get no questions. [38:54.770 --> 38:56.330] What part of that don't you understand? [38:56.770 --> 38:57.110] Yes, sir. [38:57.190 --> 38:59.890] You get to come to my house, you know, and you want to ask me questions here. [39:00.530 --> 39:11.510] Just to elaborate on what the Cisco guy just said there, if you say your switch port is non-negotiated, you won't send out VTP packets so it won't try to negotiate with Trump. [39:11.730 --> 39:18.370] If you send anything with a tag, even though you have 10 of them, it's going to see that and it's going to shut your switch port down because it's only an access code. [39:18.750 --> 39:20.550] It doesn't want to see anything as a point-point header. [39:20.950 --> 39:25.570] The other thing you touched on with VTP, VTP is only transmitted over the native VLAN and Trump. [39:26.110 --> 39:29.230] So if you say your native VLAN is something private, you still use VTP. [39:29.230 --> 39:32.070] If you want to watch out for it's revision number. [39:32.270 --> 39:40.170] If you add a switch to a network with a higher revision number than anything else, the same domain, every other switch in the domain automatically gets reconfigured. [39:40.730 --> 39:44.770] And it's a classic case, if you configure something in a lab, you never let it talk to you. [39:48.250 --> 39:50.190] Now I have two questions for you now. [39:51.790 --> 39:54.770] First question is, what switch are you using? [39:54.890 --> 39:57.190] Second one is, what cat OS are you using? [39:57.350 --> 39:58.870] Because that's the most important thing. [39:58.870 --> 40:05.080] That's why I made sure we said these were older switches that small businesses are still using today. [40:06.830 --> 40:08.560] Anything past 2001? [40:10.530 --> 40:11.650] All right. [40:12.170 --> 40:14.850] After the presentation, can we just pull off to the side? [40:15.060 --> 40:17.480] I definitely want to get more information about this. [40:18.480 --> 40:19.310] Anybody else? [40:19.310 --> 40:19.980] Yes. [40:19.980 --> 40:20.210] Yes, sir. [40:23.900 --> 40:24.840] A little bit. [40:25.060 --> 40:27.040] He's more of the... [40:27.040 --> 40:30.360] Yeah, I was going to say, we didn't do it on the attacks that we tried on. [40:42.430 --> 40:42.830] Yeah. [40:59.520 --> 41:00.500] You're right about that. [41:09.950 --> 41:10.350] Okay. [41:18.700 --> 41:19.320] What do you... [41:19.320 --> 41:21.320] I was going to say, what are you using the CDP for? [41:32.220 --> 41:32.900] Yeah. [41:56.220 --> 41:56.900] It's... [41:56.900 --> 42:01.920] That's why we really say, shut CDP off if you... [42:01.920 --> 42:02.540] Yeah. [42:03.420 --> 42:03.720] Yeah. [42:03.920 --> 42:04.140] Right. [42:06.620 --> 42:10.100] And that's why CDP is so, so... [42:10.100 --> 42:12.980] Excuse my language, but shitty protocol. [42:12.980 --> 42:13.380] Yeah. [42:16.030 --> 42:16.790] No, no. [42:19.030 --> 42:20.110] No, I haven't. [42:20.190 --> 42:20.690] I haven't. [42:20.810 --> 42:21.490] I haven't. [42:21.630 --> 42:21.790] I haven't. [42:21.790 --> 42:22.650] We didn't... [42:22.650 --> 42:24.530] We didn't test it on there. [42:25.130 --> 42:26.150] Any other questions? [42:27.830 --> 42:29.710] I wanted to add something real quick. [42:30.110 --> 42:40.690] You know, the slides, the earliest slides, I noticed down in the lab downstairs, on the switch, they were using the 3650, was it? [42:41.650 --> 42:42.010] Yeah. [42:42.010 --> 42:45.450] I know you could have ran the attack, with either cap on that switch. [42:45.870 --> 42:50.030] So I hope you guys, a lot of you guys, didn't check your email on the network. [42:50.890 --> 42:53.850] I don't know who goes to DEFCON here, but there's a wall of sheep. [42:54.890 --> 42:58.850] So, I know if you check your email, you know, on these networks, you'll be on the wall of sheep. [43:01.710 --> 43:03.810] Yeah, definitely. [43:04.230 --> 43:05.870] I know what you're talking about. [43:06.050 --> 43:07.850] You was blasting our poison all day, huh? [43:08.810 --> 43:08.970] Yeah. [43:09.690 --> 43:10.170] Uh-huh. [43:10.610 --> 43:11.230] There you go. [43:13.390 --> 43:15.750] Now you know why this is still relevant today. [43:16.750 --> 43:18.310] So, any other questions? [43:19.150 --> 43:20.050] All right, guys. [43:20.370 --> 43:21.430] We'll definitely speak. [43:21.570 --> 43:21.910] Thank you. [43:21.910 --> 43:22.550] Thank you. [43:22.630 --> 43:22.750] Thank you. [43:22.750 --> 43:23.690] Thank you, everyone for coming.