nerdexam
EC-Council

312-50V11 · Question #162

An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?

The correct answer is A. He will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer. After spoofing the root bridge via STP manipulation, the attacker configures a SPAN session to mirror all switch traffic to their own machine for passive interception.

Sniffing

Question

An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?

Options

  • AHe will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer.
  • BHe will activate OSPF on the spoofed root bridge.
  • CHe will repeat this action so that is escalates to a DoS attack.
  • DHe will repeat the same attack against all L2 switches of the network.

How the community answered

(54 responses)
  • A
    67% (36)
  • B
    11% (6)
  • C
    6% (3)
  • D
    17% (9)

Why each option

After spoofing the root bridge via STP manipulation, the attacker configures a SPAN session to mirror all switch traffic to their own machine for passive interception.

AHe will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer.Correct

As the spoofed root bridge, the attacker controls the Layer 2 topology and can configure a SPAN (Switched Port Analyzer) session to mirror traffic from other switch ports to their own, enabling full passive capture of all network traffic including credentials and sensitive data.

BHe will activate OSPF on the spoofed root bridge.

OSPF is a Layer 3 routing protocol entirely unrelated to STP exploitation; the attacker already controls the Layer 2 broadcast domain and has no reason to activate a routing protocol on the spoofed bridge.

CHe will repeat this action so that is escalates to a DoS attack.

The primary objective after gaining root bridge control is traffic interception for data theft, not denial of service; causing instability would alert defenders and disrupt the attacker's own eavesdropping.

DHe will repeat the same attack against all L2 switches of the network.

Repeating the attack on all switches is unnecessary because spoofing the root bridge already causes all traffic in the broadcast domain to flow through the attacker-controlled device.

Concept tested: STP root bridge spoofing and traffic interception

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/spantree.html

Topics

#STP manipulation#root bridge spoofing#SPAN#Layer 2 attacks

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice