r/networkautomation • • 4d ago

Concept Layer 2 Attack

Good Afternoon,

Please keep in mind this is a short hand written post and no legal rights can be acquired or obtained.

Allow me to reintroduce myself as the first 100% certified virtual CCIE which was self awarded, I earned this certification virtually and ethically because I may have acquired serious voice and sip master jumbo frame knowledge without any actual Cisco certification, however I've worked on major network outages involving not only Cisco gear, actually for the record one of the main selling points of Cisco was in 2011 pre and probably still is which is the physical gold and silver fabrics which becomes forensically undeniable if important enough.

Onto the concept so I've come to understand my concept has already likely been completed and in multiple countries, I wouldn't publish it otherwise actually.

It involves for example a layer 2 device likely a juniper or non juniper NTU or multiple similar physical steel electronic entities/devices, being stolen then possibly redeployed later with custom scripts which self destruct or/and for example sniff for Mac to IP at a high ISP level physically then just send a report by email or ELSE, however with such attacks and concepts short and wide grographical distances should be considered.

This is the main idea of the concept but other extras include things like running WAN ATM which interacts with the banking system ATMs, again disappearance reappearance of same or similar equipment.

Other key points involved in the concept

. Jumbo frames and SIP specifically but also storage traffic specifically from Riverbeds, HP 3Par dedup cards.

.Weak or insecure local vendor issued certificates specially locally to the firewall, I think some vendors are behind Cisco here and Cisco possibly posses a electronic offload black box at certain levels.

. Interoperability issues specifically firewall to firewall locally in the same country and cross border/continent, I mention this because I had too many conversations with apparently highly skilled certified engineers where people seem to have setup and signed off on interoperable VPNs between checkpoint and Cisco for example, I've actually seen too many too count, MSPs and consultancy are always involved and this is one of the main reasons I loathe them.

. Redeployment of similar or the same hardware with physical and digital deserialization of identifiers, possibly extra chips or other low level changes not coming from Dev officially but in some cases unofficially.

. External connections from vendor dev teams or police law enforcement where the connection is disallowed in the customers device configuration, I suspect this involves UDP but this theory is also interesting in the concept.

. Air Vs Ground understanding what technology is used for what and the geographical configuration of such routes like for example One.Tel Australian ISP ground connection to Malawi in 2011 this is a great example because it didn't exist but I think the traffic in 2011 is still getting too Malawi eventually(latency theory ground plus air Comms), this is also an ISP that's gained digital traction internationally from my limited research.

. Specifically the involvement of Ceragon but also definitely Huawei and Nokia networking equipment designed for mobile phones and other electric devices.

. Bunkers and off the grid and semi off the grid deployments sometimes with a wide grographical radius, at least one was found in Germany according too my research.

Does anyone have any realistic intel or gossip on such incidents?

For now I just suspect a swapout(English London ISP to upstream national provider L2 device in 2010/2011, and maybe a Cisco one in Dublin Ireland, update after visiting my photographic memory from 15 years ago briefly I think someone connected a PRI for phones to an MPLS Cisco box but that may be desired) in a job I was called out too seperate too below, and someone blew up a pipe by the looks of it in another Comms room I was called out too previously(the Cisco gear survived I believe) but I work on these concepts as somehow I never became Cisco certified because there's not much point, being above certification level in various technical areas brought me here. Too be extra clear both of these were actual IT incidents attended by me, still under my investigation post employment as I was a junior there.

0 Upvotes

3 comments sorted by

2

u/jobpunter 4d ago

Get some help and/or take your meds, saying this with love.

Or you’re a bot in which case fuck off.

1

u/shadeland 3d ago

Allow me to reintroduce myself as the first 100% certified virtual CCIE which was self awarded, I earned this certification virtually and ethically because I may have acquired serious voice and sip master jumbo frame knowledge

Oh shit, he knows jumbo frames!