Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think even without metadata server replacement this attack would still be painful. The ability to reconfigure network on a victim sounds painful


That is true, I was thinking specifically about the metadata and SSH keys. But DHCP can also set DNS servers, NTP servers, and other things that can either cause disruptions or be used to facilitate a different attack.

There might be a persistence issue, it seems like part of this attack was that the IP was persisted to /etc/hosts even after the real DHCP server took over again. But even just writing to /etc/hosts could open the door redirecting traffic to an attacker controlled server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: