Saturday, October 30, 2021

Is PPPoE an attack vector?

How dangerous are PPPoE Ethernet frames? I’ve always assumed you can tag them and put them on a VLAN and have them arrive at a Linux interface running pppd.

If I do this, can anyone on the Internet now get on that particular VLAN? Are they safely encapsulated inside PPPoE, or is it riskier than that?

My site has a dumb DSL to Ethernet modem at one end but the actual machine running pppd is at the other end, so the two talk over a VLAN. That’s not going to fly though unless the nature of PPPoE means the only attack surface is pppd itself, and not the VLAN or switch in between.



No comments:

Post a Comment