From: network security technology blog
Today, I updated my article and had a holiday with hoho. "" We found that many VPS used subnet isolation during previous penetration. So I want to test whether subnet isolation can completely solve ARP IN A CIDR block.
The effect of slice is gateway isolation. Let's test that, since it is subnet isolation, we can modify the subnet and gateway.
After the modification, We will scan the entire network segment.
We can see that the entire network segment has been scanned, And the MAC address is also different. This shows that the effect has been achieved. To be more authentic, we use an illegal site for testing.
This is the SF station.
This kind of subnet isolation has been broken through, which indicates that subnet isolation is not a good method.
To prevent arp attacks, we recommend that you use a VLAN or bind a MAC address.