skip to content

Your staging DHCP server sits on the office VLAN: how does a client tell its lease from a rogue's?

level: middleimportance: nice to knowfreq 33%

answer

  1. the client is filling blanks, not judging
  2. no server identity anywhere in the exchange
  3. the misconfiguration looks identical
  4. short lease is a habit, not a rule
  5. intent lives off the wire

basics

~20 s

It cannot. A client validates no server identity and takes the first acceptable answer, so a misplaced staging server and a hostile one are identical on the wire. Rogue is a claim about ownership, not about the packets.

solid answer

~50 s

There is nothing in the exchange for the client to check. It broadcasts a request and accepts the first well-formed answer that reaches it: no server credential, no signature, no allowlist. So a staging server a competent administrator left plugged into the wrong VLAN produces exactly what an attacker produces - hosts configured with a gateway and resolver the network's owners did not intend. The same holds on the other route, where a high-availability pair announcing a virtual address makes the same on-wire claim as a takeover. Attackers often leave optional tells - a very short lease, answering faster than the real server, addresses outside the real pool - but none is required, and a careless staging server can produce all of them. The distinction lives off the wire: who owns that port, and was the change intended.

code

text · 12 lines
text
client broadcasts a configuration request

  answer A                       answer B
    from hw    00:1a:2b:0e:41:07   00:50:56:c1:9f:22
    offered    10.20.4.63          10.20.4.63
    gateway    10.20.4.1           10.20.4.87
    resolver   10.20.4.1           10.20.4.87
    lease      8h                  2m
    ...

the client verifies no sender identity on either answer;
the short lease in B is a habit, not a required property

go deeper

for a junior

Remember that a host takes the first configuration answer it gets and checks nothing about who sent it. That single fact answers the question before any detail about the exchange comes up.

for a middle

Be ready to explain why an accidental server and a hostile one are identical at the point of receipt, and to list the attacker's usual habits while making clear that none of them is required.

for a senior

Show that you separate the event from its provenance: identical wire behaviour, different ownership. Be able to say why a misplaced staging server is a genuine finding about the segment rather than a mistake to be waved away.

for a principal

Own the conversation with the administrator whose staging server caused it. The organisation just got free evidence that any port on that segment can reconfigure hosts; the outcome should be a change to the segment, not a warning to a person.

## The client is not a judge When a host solicits configuration, it is not evaluating a claim; it is filling in blanks. It broadcasts, it receives, and it uses the first answer that parses and is acceptable. There is no server identity in that decision. No secret is shared in advance, no signature is verified, no client ships with a list of servers it is willing to believe, and nothing in the exchange lets a host prefer the answer that comes from the machine its owners bought. This is not an oversight: bootstrap configuration must work for a device that knows nothing at all, and anything a client could check would have to be configured into the client first, which is precisely the problem being solved. The direct consequence is the one candidates miss. **Maliciousness is not a property of the packets.** A staging server that a network administrator left on the wrong VLAN over a weekend emits the same class of message, gets accepted by the same rule, and reconfigures the same hosts as an attacker's laptop. The hosts cannot separate them because there is nothing to separate them by. Whether an event is an intrusion or a Friday-afternoon mistake is a fact about ownership and intent, held entirely off the segment. ## What differs, and why you cannot lean on it Attackers do tend to leave asymmetries, and it is worth being able to list them while being clear that each is optional: - **A very short lease.** An attacker who wants hosts to come back to them soon can hand out a lease measured in minutes rather than hours. Nothing requires it; a longer one holds the position just as well and looks perfectly ordinary. - **Answering fast.** First acceptable answer wins, so an attacker answering from a laptop on the same segment is often quicker than a server several hops away. But a staging server sitting on the same segment as the clients is also nearer than the production one, and so is also quicker. - **An address or gateway outside the real ranges.** An attacker who does not know the estate's addressing hands out something that does not fit. An attacker who spent ten minutes watching the segment hands out something that fits perfectly - and a staging server configured for a lab range hands out something that fits nothing at all. Every one of these can be absent from a real attack and present in a benign one. Treating any of them as the definition of "rogue" gets the direction of the claim backwards. ## The same shape on the other route This is not peculiar to configuration answers. Claiming to own an address on the wire has a legitimate twin too: a high-availability pair failing over announces that a virtual address has moved to a new hardware address, which is on the wire an assertion that this machine now owns an address it did not own a second ago. A misconfigured duplicate address produces a similar contest. The property that makes takeover possible - an unauthenticated claim that the segment believes - is exactly the property that makes legitimate movement possible, and therefore the property that makes the two indistinguishable at the point of receipt. ## What this means for how you talk about it Three things follow, and they are what an interviewer is listening for. First, **the wire cannot classify intent**, so any confident statement of the form "this traffic was an attack" is really a statement about provenance: which port, which device, whose change, authorised or not. On an authorised on-site assessment whose brief permits first-hop takeover and nothing else, the assessor's traffic is by construction identical to the thing it is imitating - that is the point of the exercise. Second, **the fix is not a better check in the client.** A client that could tell the difference would need to have been told, in advance and by some trusted path, which servers to accept - which is a segment-level arrangement, not a protocol nicety. Third, **a benign true positive is still a finding.** A staging server on the wrong VLAN is not an attack, but it demonstrates, with evidence, that any device on that segment could have done the same thing. The organisation learned the exposure is real without paying for an intruder to prove it, and the honest reading of the event is that the segment - not the administrator - is what needs changing.

  • What tells does an attacker usually leave, and why can none of them be relied on?
    Typically a very short lease so hosts return quickly, a faster answer than the real server, and sometimes addressing that does not fit the estate. Each is optional - an attacker who knows the environment can avoid all three - and a staging server on the wrong VLAN can exhibit every one of them, so they are habits rather than definitions.
  • Does the other route to the first hop have a benign twin as well?
    Yes. A high-availability pair failing over announces that a virtual address now lives at a different hardware address, and an accidental duplicate address produces a competing claim. Both are unauthenticated assertions that the segment believes, which is the same property a takeover uses, so at the point of receipt they are the same event.
  • If the client cannot check, where does a real distinction come from?
    From knowledge the segment does not carry: which port a device is on, who owns that device, whether a change was requested and approved. That is provenance, not protocol. It is also why the durable answer is arranging in advance which devices may speak on the segment rather than asking clients to be more discerning.

Two people shout directions at a lost tourist at the same moment. The tourist follows the first voice, and nothing about the voice reveals whether the speaker is a helpful local or someone sending them into an alley.

saying these in an interview costs you the question

  • Says the client checks the server's identity
  • Treats a short lease as proof of malice
  • Assumes a legitimate server always answers first
  • Calls a misplaced staging server a false positive
  • Believes the packets themselves carry intent

context