CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester on an internal network engagement floods a switch segment with forged DHCPDISCOVER packets to exhaust the legitimate DHCP server's address pool, then stands up an attacker-controlled DHCP server that assigns clients a malicious default gateway, enabling traffic interception. What is this attack called?
- ADNS cache poisoning
- BARP spoofing
- CVLAN hopping
- DDHCP starvation attack
Show answer & explanationAnswer & explanation
Correct answer: D. DHCP starvation attack
Exhausting the DHCP pool with forged requests and then serving malicious configuration via a rogue DHCP server is a DHCP starvation attack, often paired with rogue DHCP setup to perform man-in-the-middle attacks. ARP spoofing manipulates ARP caches directly, VLAN hopping bypasses VLAN segmentation, and DNS cache poisoning corrupts DNS resolver records.
Why the other options are wrong
- A. DNS cache poisoning corrupts DNS resolution records, not DHCP address leasing.
- B. ARP spoofing manipulates ARP tables to redirect traffic, not DHCP pool exhaustion.
- C. VLAN hopping uses trunking or double-tagging tricks to cross VLAN boundaries, unrelated to DHCP.
DHCP Starvation Attack
An attack where an adversary floods a network with forged DHCP request packets to exhaust the available IP address pool, often followed by deploying a rogue DHCP server to control client network configuration.
- Exhausts legitimate DHCP server's lease pool with spoofed MAC addresses
- Often paired with a rogue DHCP server for MITM attacks
- Tools like Yersinia or dhcpstarv can automate the flood
Memory trick: Starve the pool, then serve poisoned addresses