Soru

Zorluk: ZorNetwork and Wireless Attack Indicators

A network security administrator examining packet captures from an enterprise core switch notices several anomalous frames originating from an untrusted workstation segment. The captured frame header displays an outer 802.1Q tag corresponding to VLAN 1 (the native VLAN) and an inner 802.1Q tag designated for VLAN 50 (the secure database subnet). Which of the following network attack indicators is demonstrated in this scenario?

  1. VLAN hopping via double-taggingCevap
  2. B
    ARP poisoning via gratuitous ARP injection
  3. C
    DNS cache poisoning via transaction ID spoofing
  4. D
    MAC flooding via CAM table exhaustion

Cevap

The scenario describes VLAN hopping via double-tagging.
VLAN hopping via double-tagging occurs when an attacker crafts a packet with two 802.1Q tags. The initial switch removes the outer tag because it matches the native VLAN assigned to the trunk link, then forwards the frame. The recipient switch evaluates the inner tag and delivers the payload directly into the targeted VLAN, bypassing firewall and access control boundaries.

Adım Adım Çözüm

1
Analyze the frame structure from the packet capture log.
The frame contains nested 802.1Q headers: an outer tag matching the native VLAN of the switch trunk and an inner tag targeting a restricted subnet VLAN.
When a switch configured with a native VLAN receives a frame with an outer tag matching that native VLAN, it strips the outer header without rewriting and forwards the frame out trunk interfaces. The secondary switch then reads the inner tag and delivers the frame to the target VLAN.
2
Correlate frame anomalies with recognized attack vectors.
Encapsulating two 802.1Q tags to bypass VLAN boundaries is the signature mechanism of a double-tagging attack.
This technique exploits switch trunking behavior and implicit trust of native VLAN traffic to achieve unauthorized cross-VLAN frame injection.

Anahtar Kavram

VLAN Hopping Indicators and 802.1Q Double-Tagging
Bu soruyu puanla