Skip to main content
AD Academy
DHCP and Network Preparation
Intermediate18 minLast updated: Topic 2 of 5

Rogue DHCP and Network Threats

DHCP Starvation, Rogue Server, DHCPv6, and mitm6 — and their defenses.

Not read

What you will learn here

  • Main attack vectors
  • Defenses
  • DHCP Starvation, Rogue Server, DHCPv6, and mitm6 — and their defenses.

Worth reading first:DHCP and Integration with Active Directory

DHCP is an unauthenticated protocol: the client accepts the first response it receives. An attacker with physical or virtual access to the network can exploit this to make itself the Gateway and DNS for the victim — i.e., a full Man-in-the-Middle.

Main attack vectors

  • Rogue DHCP Server — a fake server that hands out the attacker's Gateway and DNS, enabling eavesdropping on all traffic.
  • DHCP Starvation — flooding the legitimate server with requests using spoofed MAC addresses until the Scope is exhausted (DoS), leaving the rogue server as the only one responding.
  • mitm6 / DHCPv6 — Windows prefers IPv6. The attacker responds to DHCPv6 requests and sets itself as DNS, then performs to or ADCS.
  • DNS Hijack via Option 006 — redirecting the client to the attacker's DNS server and spoofing the 's location.
  • Unsecured Dynamic Updates — overwriting DNS records of legitimate servers.

הלקוח שולח Discover. שרת DHCP מזויף (Rogue) מגיב קודם או שהשרת הלגיטימי מושתק (DHCP Starvation), ומחלק Lease עם Gateway ו־DNS של התוקף. הלקוח פונה ל־Fake DNS שמפנה את ה־Domain Controller לשרת התוקף. התוקף מבצע Man-in-the-Middle ו־NTLM Relay ל־LDAP או ADCS ומשיג גישה לדומיין. נקודות שליטה: DHCP Snooping מסנן תשובות DHCP רק מפורטים Trusted, 802.1X מונע חיבור מכשירים לא מורשים, RA Guard חוסם DHCPv6/RA מזויפים, ו־Secure Dynamic Updates שומר על רשומות DNS.

Defenses

  • on switches — only defined (Trusted) ports may send DHCP responses.
  • / — preventing unapproved devices from connecting to the network.
  • DHCP Authorization in — blocks unauthorized Windows servers (does not block Linux/scripts).
  • Blocking DHCPv6 or disabling IPv6 where it's not in use, and RA Guard on switches.
  • Enforcing Secure Dynamic Updates on zones integrated with .
  • Monitoring: Conflict events, anomalous Leases, and unexpected detailed traffic.
# Locating authorized DHCP servers in AD (anything outside the list is suspicious)
Get-DhcpServerInDC

# Checking for address conflicts - a possible sign of a Rogue Server
Get-DhcpServerv4Scope | Get-DhcpServerv4Lease -AllLeases |
  Where-Object { $_.AddressState -like "*Conflict*" }

# Is DHCPv6 active and listening on the server
Get-DhcpServerv6Binding
powershell
Architecture and Theory — Under the Hood

Rogue DHCP is an unauthorized DHCP server — sometimes a home router connected by mistake, and sometimes an attacker device running Yersinia/Ettercap. Since DHCP is Broadcast, the computer takes the first response — meaning the faster one.

  • Windows DHCP is authorized in , but non-Windows DHCPs (Linux, routers) are not blocked at the AD level.
  • Classic attack: Rogue DHCP advertises attacker's Gateway → MITM on all traffic.
  • Protection at the switch level: marks ports as Trusted (only the real DHCP port), and other ports are blocked.
  • Complementary: Dynamic ARP Inspection () and IP Source Guard.
Practical Configuration (PowerShell / GUI)
! Cisco - DHCP Snooping
SW(config)# ip dhcp snooping
SW(config)# ip dhcp snooping vlan 10,20
SW(config)# interface gi0/24
SW(config-if)# ip dhcp snooping trust
SW(config)# interface range gi0/1-23
SW(config-if-range)# ip dhcp snooping limit rate 15
bash
# Detect Rogue DHCP from Windows
dhcploc.exe 10.0.0.5
Get-DhcpServerInDC   # Only authorized ones
powershell
Real-world Scenarios in an Organization
  • Engineer connected a TP-Link router in a branch → the entire branch lost internet. The solution was enabling Snooping.
  • Pentester uses + Rogue DHCPv6 → DNS replacement for MITM on SMB/HTTP.
Diagnosis and Troubleshooting
  • Users receive a strange IP (192.168.1.x instead of 10.0.0.x) — Rogue.
  • drops ports? → Check trust on Uplinks and sufficient rate limit.
  • IPv6: RA Guard in addition to DHCPv6 Guard — a Rogue Router Advertisement is no less dangerous.
Glossary and Quick Command Line
  • Snooping + + IPSG = trio against MITM.
  • — a more complete solution, also authenticates the device.
  • dhcploc / Wireshark bootp — quick detection tools.

Check yourself

What is the most effective network-level defense against a Rogue DHCP Server?

Why is mitm6 especially dangerous in an AD environment?

Was this page helpful?