A network security team investigates an incident where employees on a corporate LAN segment report intermittent connectivity drops and redirection to an untrusted portal. Network packet captures reveal two distinct anomalous activities: a rapid influx of DHCP DISCOVER frames generated using spoofed source MAC addresses to exhaust available IP pool leases, followed by unauthorized DHCP ACK messages directing hosts to use an attacker-controlled default gateway. Which TWO of the following attack types were executed during this incident?
- DHCP Starvation attackCevap
- Rogue DHCP server attack establishing an on-path positionCevap
- CDNS cache poisoning attack targeting external resolver records
- DMAC flooding attack targeting switch CAM tables
Cevap
The correct attack types involved are the DHCP Starvation attack and the Rogue DHCP server attack establishing an on-path position.
The incident combines DHCP starvation and a rogue DHCP server attack. Flooding DHCP DISCOVER packets with spoofed MAC addresses depletes the legitimate server's available IP leases. Once legitimate leases are exhausted, the attacker's rogue DHCP server responds to client requests with unauthorized IP parameters, setting the attacker's machine as the default gateway to intercept client traffic.
Adım Adım Çözüm
Anahtar Kavram
Identifying DHCP Starvation and Rogue DHCP On-Path Attack Vectors
Tahmini Süre:2m 0s