
272727
© 2002, Cisco Systems, Inc. All rights reserved.
l2-security-bh.ppt
Double Encapsulated 802.1q VLAN
Hopping Attack
¥ Send double encapsulated 802.1Q frames
¥ Switch performs only one level of decapsulation
¥ Unidirectional traffic only
¥ Works even if trunk ports are set to off
Attacker
Note: Only Works if Trunk Has the
Same Native VLAN as the Attacker
Note: Only Works if Trunk Has the
Same Native VLAN as the Attacker
Victim
802.1q, 802.1q
802.1q, Frame
Strip off First,
and Send
Back out
Frame
Commentaires sur ces manuels