312-50V11 · Question #162
An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?
The correct answer is A. He will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer. After spoofing the root bridge via STP manipulation, the attacker configures a SPAN session to mirror all switch traffic to their own machine for passive interception.
Question
An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?
Options
- AHe will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer.
- BHe will activate OSPF on the spoofed root bridge.
- CHe will repeat this action so that is escalates to a DoS attack.
- DHe will repeat the same attack against all L2 switches of the network.
How the community answered
(54 responses)- A67% (36)
- B11% (6)
- C6% (3)
- D17% (9)
Why each option
After spoofing the root bridge via STP manipulation, the attacker configures a SPAN session to mirror all switch traffic to their own machine for passive interception.
As the spoofed root bridge, the attacker controls the Layer 2 topology and can configure a SPAN (Switched Port Analyzer) session to mirror traffic from other switch ports to their own, enabling full passive capture of all network traffic including credentials and sensitive data.
OSPF is a Layer 3 routing protocol entirely unrelated to STP exploitation; the attacker already controls the Layer 2 broadcast domain and has no reason to activate a routing protocol on the spoofed bridge.
The primary objective after gaining root bridge control is traffic interception for data theft, not denial of service; causing instability would alert defenders and disrupt the attacker's own eavesdropping.
Repeating the attack on all switches is unnecessary because spoofing the root bridge already causes all traffic in the broadcast domain to flow through the attacker-controlled device.
Concept tested: STP root bridge spoofing and traffic interception
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/spantree.html
Topics
Community Discussion
No community discussion yet for this question.