Synopsis
Routing tables can be modified.
Description
The remote RIP listener accepts routes that are not sent by a neighbor.
This cannot happen in the RIP protocol as defined by RFC2453, and although the RFC is silent on this point, such routes should probably be ignored.
A remote attacker might use this flaw to access the local network if it is not protected by a properly configured firewall, or to hijack connections.
Solution
Either disable the RIP listener if it is not used, use RIP-2 in conjunction with authentication, or use another routing protocol.
Plugin Details
File Name: rip_poison.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: Services/udp/rip