CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester on an internal network wants to intercept traffic between a target workstation and the default gateway. The tester runs arpspoof to send forged ARP replies to both devices, causing each to update its ARP cache with the attacker's MAC address. Which type of attack is being performed?
- AVLAN hopping
- BDNS cache poisoning
- CARP spoofing / on-path attack
- DDHCP starvation
Show answer & explanationAnswer & explanation
Correct answer: C. ARP spoofing / on-path attack
ARP spoofing sends forged ARP replies to associate the attacker's MAC address with the IP addresses of the victim and gateway, positioning the attacker on-path to intercept, modify, or relay traffic between them.
Why the other options are wrong
- A. VLAN hopping exploits trunking misconfigurations to access other VLANs, not ARP tables.
- B. DNS cache poisoning corrupts DNS resolution records, not the local ARP cache.
- D. DHCP starvation exhausts the DHCP address pool, an unrelated denial-of-service technique.
ARP Spoofing
An on-path (man-in-the-middle) attack that sends forged ARP replies to associate the attacker's MAC address with a victim's or gateway's IP address, redirecting traffic through the attacker.
- Exploits the lack of authentication in ARP
- Commonly performed with tools like arpspoof or Ettercap
- Enables traffic sniffing, modification, or SSL stripping
Memory trick: ARP lies about who owns which address, funneling traffic through you.