During a security audit of a dual-stack enterprise LAN, network administrators discover that several IPv4-configured workstations are unexpectedly redirecting web traffic to an untrusted external IP address. Packet captures reveal that these workstations regularly receive unsolicited ICMPv6 Router Advertisement (RA) packets from a non-gateway host. These RA frames specify an unknown link-local IPv6 address as the default gateway and assign a rogue IPv6 DNS server. Which of the following statements accurately describe this network attack and its operational impact? (Select TWO.)
- The attacker is exploiting IPv6 Router Advertisements to conduct an On-Path (Man-in-the-Middle) attack via SLAAC spoofing.Cevap
- Dual-stack client operating systems naturally prefer IPv6 DNS resolution over IPv4, causing traffic to route through the rogue IPv6 gateway.Cevap
- CThe incident occurs because MAC address table exhaustion forced the local switch into a fail-open state, broadcasting unicast frames to all switchports.
- DThe compromised state was caused by the attacker altering authoritative AAAA records directly on the enterprise internal DNS server.
Cevap
The attack is an On-Path (Man-in-the-Middle) attack executed via rogue ICMPv6 Router Advertisement (RA) / SLAAC spoofing, which leverages the default host OS behavior of prioritizing IPv6 traffic and DNS resolution over IPv4.
In dual-stack network environments, transmitting unauthorized ICMPv6 Router Advertisements (RAs) allows an attacker to automatically configure client network settings via SLAAC. Because modern operating systems default to prioritizing IPv6 connectivity and DNS resolution over IPv4, hosts will send their DNS requests and outbound traffic to the attacker's rogue IPv6 link-local gateway, establishing an On-Path (Man-in-the-Middle) position.
Adım Adım Çözüm
Anahtar Kavram
Rogue IPv6 Router Advertisement (RA) Spoofing and On-Path Attacks
Tahmini Süre:2m 0s