GCIH · Question #578
An attacker is attempting to sniff packets on a switched network. He has forced his network interface to run in promiscuous mode, and set up IP forwarding on his machine. All packets transmitted to…
The correct answer is D. Send a gratuitous ARP reply to the victim machine. The technique outlined in this question is ARP cache poisoning. The attacker would send a gratuitous ARP to the victim machine, mapping the default gateway's IP address to the attacker's MAC address. As packets come through his computer, they are sniffed and forwarded to the…
Question
An attacker is attempting to sniff packets on a switched network. He has forced his network interface to run in promiscuous mode, and set up IP forwarding on his machine. All packets transmitted to his machine will be forwarded to the network's default gateway. What should the attacker do next to sniff packets coming from a victim's machine?
Options
- ASend a spoofed DNS response to the victim
- BChange the attacker's IP address to match that of the victim
- CSend a series of RST packets to the victim machine
- DSend a gratuitous ARP reply to the victim machine
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C7% (2)
- D79% (23)
Explanation
The technique outlined in this question is ARP cache poisoning. The attacker would send a gratuitous ARP to the victim machine, mapping the default gateway's IP address to the attacker's MAC address. As packets come through his computer, they are sniffed and forwarded to the legitimate default gateway. Changing the attacker's IP address to match that of the victim would simply create an IP address conflict, and would not enable the attacker to sniff traffic originating from the victim's computer. Sending a series of RST packets or a spoofed DNS response to the victim would no enable the attacker to sniff packets.
Topics
Community Discussion
No community discussion yet for this question.