← Back to Attack / Defense Lab
OSI LAYER 2 // Data Link Layer

Rogue DHCP Server

A rogue DHCP server provides unauthorized network configuration, potentially directing clients to malicious gateways or DNS resolvers.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

Clients accept DHCP offers according to protocol behavior. An unauthorized responder can therefore influence addressing and network configuration if switch controls are weak.

02 // DETECTION

Indicators to watch

DHCP offers from unexpected ports, inconsistent gateway/DNS values, multiple DHCP responders, and sudden client configuration changes.

03 // ATTACK FLOW

Concept diagram

01Unauthorized DHCP responder↓
02Client DHCP request↓
03Rogue offer↓
04Wrong gateway / DNS↓
05Trusted DHCP ports
04 // PREVENTION

Defensive controls

Enable DHCP snooping/trusted ports, segment networks, monitor DHCP traffic, and investigate unexpected responders.

05 // SECURITY TOOL

Recommended security control

DHCP snooping + packet capture

Use a virtual LAN with synthetic clients.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.