Elements of an ARP Spoofing Attack

An attack consists of sending fake unsolicited ARP replies to host A, as Figure 6-4 shows. The attacker, host C, sends this gratuitous ARP without any MAC spoofing to host A. The content contains a new but incorrect mapping of host B's IP address to the MAC address of host C (the attacker).

Figure 6-4 ARP Spoofing: The Attack

0000.C5C0.0000

0000.CAFE.0000

Host C IP: 10.0.0.3 MAC 0000.0666.0000

Upon receipt of the faked gratuitous ARP reply, host A updates its ARP table with the new <IP, MAC> address mapping for host B, as Table 6-3 shows. This mapping, of course, is not correct, but host A has no way to detect it. Table 6-3 Host A ARP Table

IP Address

MAC Address

10.0.0.1

0000.CAFE.0000

10.0.0.2

0000.0666.0000

As soon as host A updates its ARP table, all its IP packets destined to host B are actually sent to the attacker's MAC address (host C).

Figure 6-5 shows packet flow between IP host A and host B. IP packets from host A to host B are actually first sent to host C (because host A believes that host B's MAC address is the MAC address of host C), which sniffs the packet. Typically, host C needs to resend the IP packet to the final host, host B, or else the communication breaks and users notice that something is wrong.

ARP spoofing works only in one way: The attacker (host C) intercepts only the packet flow from IP host A to host B. If the attacker wants to sniff the return traffic, he must send gratuitous ARP packets to IP host B to change its ARP table so that it contains faked mapping of host A's IP address to host C's MAC address.

Figure 6-5 ARP Spoofing: The Effect a

MAC: CAFE -> 0666 N IP: 10.0.0.1 -> 10.0.0.2 Telnet: password=xyz >

0000.C5C0.0000

0000.CAFE.0000

MAC: 0666 -> C5C0 IP: 10.0.0.1 -> 10.0.0.2 Telnet: password=xyz

0000.C5C0.0000

MAC: 0666 -> C5C0 IP: 10.0.0.1 -> 10.0.0.2 Telnet: password=xyz

Host C IP: 10.0.0.3 MAC 0000.0666.0000

Host C IP: 10.0.0.3 MAC 0000.0666.0000

Notice that the switch does exactly what it is built for: forwarding MAC frames to their destination based solely on the learned content-addressable memory (CAM) table, as Table 6-4 shows. This attack is not against a switch, however, it is against the ARP.

Table 6-4 Switch CAM Table

MAC Address

Port

0000.0666.0000

To C

0000.CAFE.0000

To A

0000.C5C0.0000

To B

If the victim, host B, is actually a router, attacker C receives all the IP packets leaving the local subnet because all nodes will send those datagrams to the attacker, who spoofed the router MAC address. But, the attacker won't receive any IP packet destined to any host on the local subnet with a single ARP spoofing attack. To receive the back traffic, the attacker runs multiple ARP spoofing attacks (by sending spoofed ARP packets to the router, pretending to be all attached nodes) to get the traffic to the local hosts.

Finally, this attack is only effective within the attacker's VLAN. More precisely, it only applies when the attacker is in the same IP subnet of both victims because ARP is only used between two hosts when they are in the same subnet.

Continue reading here: Mounting an ARP Spoofing Attack

Was this article helpful?

0 0