Hijacking Traffic Using DHCP Rogue Servers
Another DHCP exploit with devastating results consists in installing a covert DHCP server on a LAN segment, as Figure 5-4 shows.
Figure 5-4 DHCP Rogue Server
Figure 5-4 DHCP Rogue Server
Crafted Offer
IP Address: 10.10.10.101 Subnet Mask: 255.255.255.0 Default Routers: 10.10.10.1 DNS Servers: 192.168.10.4, 192.168.10.5 Lease Time: 10 Days
Crafted Offer
If a rogue DHCP server is installed on the LAN, by default, it receives DHCPDISCOVER messages from clients seeking to acquire an IP address.
IP Address: 10.10.10.101 Subnet Mask: 255.255.255.0 Default Routers: 10.10.10.1 DNS Servers: 192.168.10.4, 192.168.10.5 Lease Time: 10 Days
At this point, it is a race condition between the rogue DHCP server and the legitimate server. Because of its proximity to the clients, the rogue server probably has the upper hand. At this point, all bets are off: The rogue server can hand out options of its choosing to clients.
Which DHCP Server Will the DHCP Client Use?
When the DHCP client receives several DHCPOFFERs from different servers, which offer should it use?
In general, a DHCP client remembers the IP address it used before and, if there is an offer for this address (DHCP server being stateful offers the same IP address to the same client, if the IP address is available), the DHCP client uses this offer.
When all offers are unrelated to the client's previous IP address, the client simply uses the first offer received.
Many times, hosts obtain their domain name and domain name server IP address through DHCP. Convincing a host to use a specific (compromised) DNS server is close to the holy grail of LAN security—or insecurity, depending on your point of view!
An attacker can now attract victims to forged websites that are exact replicas of the original ones. Here, they capture credentials, account information, and other sensitive information.
Continue reading here: Port Security
Was this article helpful?