[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Xen-users] ARP-Spoofing + Xen Network script ???



> -----Original Message-----
> From: xen-users-bounces@xxxxxxxxxxxxxxxxxxx [mailto:xen-users-
> bounces@xxxxxxxxxxxxxxxxxxx] On Behalf Of Patrick Straub
> Sent: Tuesday, October 20, 2009 9:50 AM
> To: xen-users@xxxxxxxxxxxxxxxxxxx
> Subject: [Xen-users] ARP-Spoofing + Xen Network script ???
> 
> Hi xenusers,
> 
> is it possible to do a ARP-Spoof from a VM lets say DomU1 and the Dom0
> ?
> I'm currently using Xen in routed-mode which means that every DomU has
> its own ip-address and packets will be forwarded on the Dom0.
> 
> I've tested a simple ARP-Spoof within my DomU. I've tried to tell the
> Dom0 that I'm now the gateway to forward the traffic on. So I did the
> following command:
>       arpspoof -t "dom0-ip" "gw-ip"
> 
> But there was no effect?
> 
> Does anybody know why this is so? It seems that Dom0 is not accepting
> any ARP-Pakets from the Userdomains but why and how?
> 
> Thx for any answer on this.
> 
> greetings
> Patrick

I'd guess that your dom0 isn't arping for the gateway to the vif, but without 
more information, it's impossible to say.

If your Dom0's eth0 is 1.1.1.2/24, and your vif0 is 1.1.2.1/24, your dom0 isn't 
going to send an ARP for 1.1.1.1 on vif0 - that doesn't make sense to the 
routing table.

Best Regards,
Nathan Eisenberg


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.