CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
A tester wants to send traffic from a compromised access port into VLANs other than the one it is assigned to, without negotiating a trunk link. The tester crafts Ethernet frames with two stacked 802.1Q VLAN tags, relying on the switch stripping the outer tag that matches the native VLAN and forwarding the inner tagged frame to another VLAN. Which attack is being performed?
- AARP spoofing
- BDouble tagging
- CSwitch spoofing
- DDHCP starvation
Show answer & explanationAnswer & explanation
Correct answer: B. Double tagging
Double tagging is a VLAN hopping technique that exploits switches which strip only the outer 802.1Q tag matching the native VLAN, forwarding the frame with its remaining inner tag into a different VLAN, allowing one-way traffic injection. Switch spoofing instead relies on negotiating a trunk via DTP, ARP spoofing manipulates MAC-to-IP mappings on the local segment, and DHCP starvation exhausts the DHCP address pool.
Why the other options are wrong
- A. ARP spoofing poisons ARP caches and does not involve VLAN tags.
- C. Switch spoofing negotiates a trunk by mimicking a switch, unrelated to stacked tags.
- D. DHCP starvation exhausts DHCP leases, unrelated to VLAN tagging.
VLAN Hopping - Double Tagging
A Layer 2 attack where an attacker sends frames with two nested 802.1Q VLAN tags so the switch strips the outer native VLAN tag and forwards the inner-tagged frame into another VLAN.
- Exploits native VLAN untagged forwarding behavior
- One-way attack (no return traffic path)
- Mitigated by not using VLAN 1 as native VLAN and tagging native VLAN traffic
Memory trick: 'Two tags, one strip, sneak into the next VLAN' — double tagging