CompTIA Network+ (N10-009)Network ImplementationHard
A penetration tester crafts an Ethernet frame containing two nested 802.1Q VLAN tags and sends it from a host on the native VLAN of a trunk link. The goal is to have the frame processed on a VLAN the host should not have access to. Which attack is being demonstrated?
- ARogue DHCP server attack
- BMAC flooding
- CARP spoofing
- DVLAN hopping via double tagging
Show answer & explanationAnswer & explanation
Correct answer: D. VLAN hopping via double tagging
Double tagging is a VLAN hopping technique where an attacker on the native VLAN adds two 802.1Q tags; the first switch strips the outer (native VLAN) tag, and the inner tag is then forwarded onto a trunk, causing the frame to appear on a different VLAN than the attacker's actual VLAN, bypassing VLAN isolation.
Why the other options are wrong
- A. A rogue DHCP server hands out malicious IP configuration information, unrelated to VLAN tagging.
- B. MAC flooding overwhelms a switch's CAM table to force it into hub-like flooding behavior, not VLAN tag exploitation.
- C. ARP spoofing manipulates ARP tables to intercept traffic, unrelated to VLAN tag manipulation.
VLAN Hopping (Double Tagging)
An attack where a host on the native VLAN sends frames with two stacked 802.1Q tags; the first switch strips the outer tag, allowing the inner tag to reach a different VLAN than intended, bypassing VLAN segmentation.
- Only works if attacker is on the native VLAN of a trunk
- Mitigated by not using VLAN 1 as native VLAN and explicitly tagging native VLAN traffic
- Traffic is one-way, useful mainly for attacks like DoS or reconnaissance
Memory trick: Two tags, one sneaky hop across the VLAN fence.