DHCP is an unauthenticated protocol: the client accepts the first response it receives. An attacker with physical or virtual access to the network can exploit this to make itself the Gateway and DNS for the victim — i.e., a full Man-in-the-Middle.
Main attack vectors
- Rogue DHCP Server — a fake server that hands out the attacker's Gateway and DNS, enabling eavesdropping on all traffic.
- DHCP Starvation — flooding the legitimate server with requests using spoofed MAC addresses until the Scope is exhausted (DoS), leaving the rogue server as the only one responding.
- mitm6 / DHCPv6 — Windows prefers IPv6. The attacker responds to DHCPv6 requests and sets itself as DNS, then performs to or ADCS.
- DNS Hijack via Option 006 — redirecting the client to the attacker's DNS server and spoofing the 's location.
- Unsecured Dynamic Updates — overwriting DNS records of legitimate servers.
הלקוח שולח Discover. שרת DHCP מזויף (Rogue) מגיב קודם או שהשרת הלגיטימי מושתק (DHCP Starvation), ומחלק Lease עם Gateway ו־DNS של התוקף. הלקוח פונה ל־Fake DNS שמפנה את ה־Domain Controller לשרת התוקף. התוקף מבצע Man-in-the-Middle ו־NTLM Relay ל־LDAP או ADCS ומשיג גישה לדומיין. נקודות שליטה: DHCP Snooping מסנן תשובות DHCP רק מפורטים Trusted, 802.1X מונע חיבור מכשירים לא מורשים, RA Guard חוסם DHCPv6/RA מזויפים, ו־Secure Dynamic Updates שומר על רשומות DNS.
Defenses
- on switches — only defined (Trusted) ports may send DHCP responses.
- / — preventing unapproved devices from connecting to the network.
- DHCP Authorization in — blocks unauthorized Windows servers (does not block Linux/scripts).
- Blocking DHCPv6 or disabling IPv6 where it's not in use, and RA Guard on switches.
- Enforcing Secure Dynamic Updates on zones integrated with .
- Monitoring: Conflict events, anomalous Leases, and unexpected detailed traffic.