PDA

View Full Version : ZA is not protecting me against ARP poisoning attack


rOadToIS
August 17th, 2009, 08:10 PM
As you guys know, there is an option called "Enable ARP protection" under the firewall settings. Despite enabling this option, I could still ARP poison my desktop that's in the same network as my laptop and sniff all the packets. How did this happen? Am I the only one experiencing this malfunction of ZA?

jrmhng
August 18th, 2009, 08:59 AM
You will need to give some more detail on how you are doing the ARP poisoning.

rOadToIS
August 18th, 2009, 09:54 AM
I used Backtrack3 live cd to launch an ARP poisoning attack. Specifically, I used Ettercap that comes with BT3.
First I scanned for a host and got IPs for my router and my desktop. Then, I added those IPs to each target and enabled ARP poisoning, which was carried out successfully.

Dregg Heda
August 18th, 2009, 11:25 PM
This should only be possible if someone gains access to the wireless network right?

bonedriven
August 19th, 2009, 08:02 AM
So far as I know,none of those brand name firewalls can stop heavy ARP attacks. We already have had a lot of discussion about this topic in WSF.

There are some Anti-arp tools which are designed to fight ARP attack only though. You may try antiarp (http://www.antiarp.com/news_25.html),but it requests you to change your homepage if you want to continue to use the product after 15 days trial. Or you may try Kingsoft's antiarp (http://www.duba.net/download/arp.shtml).

I heard they both did well in ARP attack tests.

rOadToIS
August 19th, 2009, 10:15 AM
-{ Quote: "This should only be possible if someone gains access to the wireless network right?" }-
yes, it's only possible once you gain access to the network.

rOadToIS
August 19th, 2009, 10:16 AM
-{ Quote: "So far as I know,none of those brand name firewalls can stop heavy ARP attacks. We already have had a lot of discussion about this topic in WSF.

There are some Anti-arp tools which are designed to fight ARP attack only though. You may try antiarp (http://www.antiarp.com/news_25.html),but it requests you to change your homepage if you want to continue to use the product after 15 days trial. Or you may try Kingsoft's antiarp (http://www.duba.net/download/arp.shtml).

I heard they both did well in ARP attack tests." }-
Thank you for the info.

Dregg Heda
August 19th, 2009, 10:34 AM
Alright thanks rOadToIS!

fax
August 19th, 2009, 11:27 AM
-{ Quote: "This should only be possible if someone gains access to the wireless network right?" }- Yes, or take control of your ISP ;D

Dregg Heda
August 19th, 2009, 12:02 PM
-{ Quote: "Yes, or take control of your ISP ;D" }-

Now I'm really worried! My ISP are run by morons!;D

fax
August 19th, 2009, 12:04 PM
-{ Quote: "Now I'm really worried! My ISP are run by morons!;D" }- Mhuhuuaah, you are owned :lurking:

firzen771
August 19th, 2009, 04:17 PM
-{ Quote: "Now I'm really worried! My ISP are run by morons!;D" }-

hell i know my ISP is run by morons... but the customer support is nice at least ;D but they havent been taken over (yet...) :)

Escalader
August 22nd, 2009, 03:26 PM
-{ Quote: "So far as I know,none of those brand name firewalls can stop heavy ARP attacks. We already have had a lot of discussion about this topic in WSF.

There are some Anti-arp tools which are designed to fight ARP attack only though. You may try antiarp (http://www.antiarp.com/news_25.html),but it requests you to change your homepage if you want to continue to use the product after 15 days trial. Or you may try Kingsoft's antiarp (http://www.duba.net/download/arp.shtml).

I heard they both did well in ARP attack tests." }-


-{ Quote: "So far as I know,none of those brand name firewalls can stop heavy ARP attacks" }-

I use another brand name FW, and it does offer protection against ARP attacks.

I would want to see independent testing results from someone like Stem before accepting that ZA or any main line FW doesn't protect against ARP attacks.

In the meantime can you provide links to your test results?