802 802.1 .1x NA x NAC C & B & BYPASS SS TECHNI CHNIQUES QUES
Hack in Paris 2017 Valérian LEGRAND
802 802.1 .1x NA x NAC C & B & BYPASS SS TECHNI - - PowerPoint PPT Presentation
802 802.1 .1x NA x NAC C & B & BYPASS SS TECHNI CHNIQUES QUES Hack in Paris 2017 Valrian LEGRAND ABOUT o Valrian LEGRAND, Security consultant and Penetration Tester at Orange CyberDefense o Breaking things is my job o Why
Hack in Paris 2017 Valérian LEGRAND
CyberDefense
penetration test so it’s not that bad !”
2
Wired 802.1X
How the hell does it work ?
A Brief Overview
Bypasses FENRIR Goddammit, We Want Shells !
3
The new device
The switch (or Wireless AP)
The server responsible for checking credentials (Usually a RADIUS server)
4
5
authentication !
6
7
Standard base authentication scheme
8
is useless
example)
9
Just a quick note about what is NOT 802.1x protection
(security cameras)
network without the need to authenticate
Identity messages
device’s MAC address to the authentication server
10
BYPASS - The easy way :
fake legitimate packets
11
BYPASS - The hard way :
2001 2005
January 2011 August 2011 Standard creation Steve Riley HUB attack Abb (Gremwell blog) Marvin tool Alva ‘Skip’ Duckwall ebtables, iptables, bridge
2005
Extension of 802,1x-2001 to « allow concurrent sessions »
12
test (including Red Team)
13
FENRIR host disappear
14
Switch’s port state changes from uncontrolled to controlled
We need to keep the legitimate host’s network access up in order to bypass periodic re-authentications
15
16
From : 192.168.1.42 : 5555 To : 192.168.1.10 : 443
17
From : 192.168.1.10 : 443 To : 192.168.1.42 : 5555
18
From : 192.168.1.42 : 35180 To : 192.168.201.30 : 80
19
From : 192.168.201.30 : 80 To : 192.168.1.42 : 35180
20
From : 192.168.201.30 : 80 To : 192.168.1.32 : 35180
21
22
23
the network)
specific frames
24
(and new protocols can be added)
25
26
implemented it ! 802.1x =/= physical access protection
(Does anyone realize this kid is eating sand ?!?) 27
https://github.com/Orange-Cyberdefense/fenrir