Re: Blocking by MAC Address -



Again, it is possible to change MAC address to just about anything in few
seconds. So don't tie your security to MAC addresses...

Any MAC address is only visible and viable inside the subnet. What if I
attack you from another subnet and you don't see my MAC? Only my IP address?

--
Mike
Microsoft MVP - Windows Security

"M. Eteum" <meteum@xxxxxxxxx> wrote in message
news:u0usEEG9FHA.736@xxxxxxxxxxxxxxxxxxxxxxx
> Miha Pihler [MVP] wrote:
>> Again an attacker could still bypass 802.1x with this configuration.
>>
>> Switch will only see one MAC. What is stopping an attacker to assign
>> himself same MAC as a valid computer? There are few other ways to fool
>> switch into allowing more then one MAC per port (even if configured
>> otherwise).
>>
>> This is very well described here under: "Why 802.1X on wired networks is
>> insufficient"
>> http://www.microsoft.com/technet/community/columns/secmgmt/sm0805.mspx
>>
>
> Perhaps using 802.1X in combination with CertServices will stop bogus MAC
> address.


.



Relevant Pages

  • Re: More on caching and logging
    ... attention to the inner workings of the Mac. ... thought to getting an iPod. ... But the attacker never signed any agreement with apple, ... and far more of a security enhancement against this kind of thing. ...
    (comp.sys.mac.system)
  • RE: rogue IP address
    ... the alert from the LAN management software can be enough - if it ... if it's a D-Link MAC ... Program the switch to drop that IP address - see who screams. ... prospectus based upon the core principle concepts of security. ...
    (Security-Basics)
  • RE: rogue IP address
    ... Sorry if this seems like a dumb question, but you mentioned a "port to IP" ... Does your switch have a "port to MAC address table"? ... prospectus based upon the core principle concepts of security. ...
    (Security-Basics)
  • Re: how to test Ethernet connection
    ... A switch uses MAC addresses for ascertaining where to forward ... I was not referring to a "MAC Bridge" ... This is more secure as traffic cannot be sniffed by stations on other ports. ... Which just goes to show that 'security' is not a simple quality of which one can have more or less but a set of qualities. ...
    (Debian-User)
  • Re: the exploit that wasnt
    ... The other Mac Book Pro? ... brought Microsoft into a security discussion about Mac OS X. ... The number of security patches, ... if you were to scan random machines on the internet for a week, ...
    (comp.sys.mac.advocacy)