Soru

Zorluk: KolayNetwork and Wireless Attack Indicators

A network technician notices that several workstations on a local subnet are experiencing intermittent network connectivity issues. Upon checking the IP configurations of affected client devices, the technician discovers unexpected network settings. Which TWO of the following indicators specifically point to the presence of an active rogue DHCP server on the network?

  1. Workstations are receiving IP addresses and default gateway assignments from an unrecognized address pool.Cevap
  2. B
    Network security logs show a sudden burst of unsolicited Address Resolution Protocol (ARP) reply packets mapping different IP addresses to the same MAC address.
  3. Clients report receiving DNS server address assignments pointing to an external or untrusted IP address during lease renewal.Cevap
  4. D
    Applying static MAC address filtering on the core switch immediately mitigates the unauthorized IP address assignment issue.

Cevap

The presence of a rogue DHCP server is indicated by workstations receiving IP addresses and gateway settings from an unrecognized address pool, as well as clients receiving untrusted DNS server address assignments during DHCP lease options processing.
A rogue DHCP server operates by listening for client DHCPDISCOVER broadcasts and responding with malicious configuration settings. Key indicators include clients acquiring IP address leases outside the enterprise scope and receiving unauthorized default gateway or DNS server address settings that allow attackers to redirect client traffic.

Adım Adım Çözüm

1
Analyze how DHCP clients request network configurations
Clients broadcast DHCPDISCOVER requests and accept DHCPOFFER parameters from the fastest responding server.
Because DHCP broadcast requests are unauthenticated by default, any active server on the broadcast domain can offer lease configurations.
2
Identify anomalous DHCP configuration payloads
Receiving non-standard gateway settings, untrusted DNS server addresses, or IP addresses outside the designated scope indicates unauthorized server responses.
Attacker-controlled rogue DHCP servers alter gateway and DNS fields to execute on-path (man-in-the-middle) attacks.

Anahtar Kavram

Rogue DHCP Server Attack Indicators
Bu soruyu puanla