Gal Zror: Hacking ISPs via PPPoE
A DEF CON 30 talk about a hidden attack surface in internet service provider infrastructure. The speaker shows how vulnerabilities in PPPoE implementations and BRAS equipment used to connect subscribers can allow attackers to target ISP networks directly from client-side devices.
The talk analyzes critical vulnerabilities — including a logical DoS and a remote code execution (RCE) flaw — that could lead to full ISP infrastructure compromise, large-scale DNS poisoning, and attacks affecting thousands of users simultaneously.
The talk analyzes critical vulnerabilities — including a logical DoS and a remote code execution (RCE) flaw — that could lead to full ISP infrastructure compromise, large-scale DNS poisoning, and attacks affecting thousands of users simultaneously.