STP root takeover¶
1. Context & stakes¶
Forge BPDUs to become root bridge and reroute traffic.
Spanning Tree elects a root bridge by lowest priority and by default trusts any BPDU on any port. An attacker sending superior BPDUs becomes root, so inter-switch traffic reroutes through their machine for MITM, or flaps endlessly for denial of service. BPDU Guard and Root Guard on edge ports are the standard containment.
2. Theory¶
Spanning Tree prevents L2 loops by electing a root bridge (lowest bridge-ID) and blocking redundant links, bridges exchanging BPDUs with no authentication. An attacker emitting a superior BPDU (lower priority) becomes root, forcing traffic to reconverge through its port - a MITM or DoS via topology change.
3. Attack (PoC)¶
- Emit a superior BPDU
- Take the root role, reroute flows
4. Detection¶
Indicators to watch, and the associated IDS rule (see
netlab-ids).
5. Defense¶
- BPDU Guard, Root Guard
- PortFast limited to access ports
6. Exercise¶
Reproduce in the isolated lab (netns/veth): see lab setup.
7. Further reading¶
- IEEE 802.1D / 802.1w (RSTP)
- BPDU Guard, Root Guard
- Yersinia