Rogue DHCP Server
A rogue DHCP server provides unauthorized network configuration, potentially directing clients to malicious gateways or DNS resolvers.
Mechanism
Clients accept DHCP offers according to protocol behavior. An unauthorized responder can therefore influence addressing and network configuration if switch controls are weak.
Indicators to watch
DHCP offers from unexpected ports, inconsistent gateway/DNS values, multiple DHCP responders, and sudden client configuration changes.
Concept diagram
Defensive controls
Enable DHCP snooping/trusted ports, segment networks, monitor DHCP traffic, and investigate unexpected responders.
Recommended security control
DHCP snooping + packet capture
Use a virtual LAN with synthetic clients.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.