Hijacking Traffic Using DHCP Rogue Servers

Another DHCP exploit with devastating results consists in installing a covert DHCP server on a LAN segment, as Figure 5-4 shows.

Figure 5-4 DHCP Rogue Server

Figure 5-4 DHCP Rogue Server

Crafted Offer

IP Address: 10.10.10.101 Subnet Mask: 255.255.255.0 Default Routers: 10.10.10.1 DNS Servers: 192.168.10.4, 192.168.10.5 Lease Time: 10 Days

Crafted Offer

If a rogue DHCP server is installed on the LAN, by default, it receives DHCPDISCOVER messages from clients seeking to acquire an IP address.

IP Address: 10.10.10.101 Subnet Mask: 255.255.255.0 Default Routers: 10.10.10.1 DNS Servers: 192.168.10.4, 192.168.10.5 Lease Time: 10 Days

At this point, it is a race condition between the rogue DHCP server and the legitimate server. Because of its proximity to the clients, the rogue server probably has the upper hand. At this point, all bets are off: The rogue server can hand out options of its choosing to clients.

Which DHCP Server Will the DHCP Client Use?

When the DHCP client receives several DHCPOFFERs from different servers, which offer should it use?

In general, a DHCP client remembers the IP address it used before and, if there is an offer for this address (DHCP server being stateful offers the same IP address to the same client, if the IP address is available), the DHCP client uses this offer.

When all offers are unrelated to the client's previous IP address, the client simply uses the first offer received.

Many times, hosts obtain their domain name and domain name server IP address through DHCP. Convincing a host to use a specific (compromised) DNS server is close to the holy grail of LAN security—or insecurity, depending on your point of view!

An attacker can now attract victims to forged websites that are exact replicas of the original ones. Here, they capture credentials, account information, and other sensitive information.

Continue reading here: Port Security

Was this article helpful?

0 0