ARP replies or a rogue DHCP lease: which route to a host's first hop costs less to hold?
answer
- one buys a path, one buys the whole configuration
- rent versus a single payment
- who gets the resolver as well
- you must be there when the host asks
- coverage per victim versus for free
basics
~20 sThe lease route is far cheaper. One answer installs the attacker as gateway and resolver for that host and then needs no upkeep. Answering for the gateway's address covers one victim at a time and must be re-asserted continuously, forever.
solid answer
~50 sPrice them, do not just name them. Answering for the gateway's hardware address works immediately against a host that is already running, but it buys a path and nothing else: it covers one victim at a time, both directions must be maintained because those mappings are re-learned constantly, and the attacker must keep transmitting for as long as the position is wanted. Winning the configuration answer is the opposite trade. It is opportunistic - a host accepts one only when it asks, at boot, on joining the segment, or when its lease runs down - but a single answer installs the attacker as both default gateway and resolver, and holds with no further effort. The reply route buys immediacy and pays rent; the lease route waits, then holds the position for free, with name resolution included.
go deeper
Know that a host learns its gateway and resolver from a configuration answer, and separately learns the gateway's hardware address from the segment. Being able to point at those two answers as the two ways in is enough at this level.
Be ready to compare the routes on cost and coverage, not just to name them: continuous re-assertion per victim versus a single answer that holds, and which of the two also hands over name resolution.
Demonstrate that you choose by window and objective - short presence against running hosts versus a longer stay that harvests configuration requests - and that you know which position leaves a visible failure behind when the attacker leaves.
Be able to explain to an owner why these two are not one finding: they differ in durability, breadth and what they hand over, so an assessment that reports them jointly understates the cheaper one.
## Two routes to the same chair, with very different bills An attacker adjacent to an office segment can occupy a host's first hop two ways. They can answer for the gateway's hardware address, so that traffic the host means for the gateway is handed to them on the wire. Or they can be the one that answers the host's configuration request, so the host is told from the outset that the attacker's address is its gateway - and its resolver. Candidates usually name both and stop. The interview value is in pricing them. ## What each hands over The reply route hands over **a path**. The victim's off-segment traffic arrives at the attacker, who must forward it onward or the victim notices immediately. Nothing else is granted: the host's idea of which resolver to ask is untouched, so the attacker only influences name lookups by interfering with them in flight. The lease route hands over **the host's whole idea of the network**. The same answer that gives the host an address gives it a default gateway and a resolver, and the attacker can put itself in both fields. Being the resolver is a qualitatively different lever from being the path: it operates before a session exists, deciding which destination a name points at, or whether it points anywhere. ## What each costs to hold This is where the routes diverge hardest. **The reply route bills continuously.** The mapping the attacker is falsifying is short-lived and constantly re-learned, so the false answer must be re-asserted for as long as the position is wanted. It must be maintained for both ends of each conversation, or traffic flows one way and breaks. And it is per-victim: covering a second host means maintaining a second set of claims, so cost scales linearly with coverage while the attacker's transmit volume climbs with it. The attacker is also now a router, obliged to forward everything correctly at line rate or be noticed by the user rather than by any instrument. **The lease route bills once.** The attacker answers, the host writes the configuration down, and the attacker's job is done. There is no re-assertion, no per-packet obligation to forward anything it does not want to forward, and coverage grows for free: every host that happens to ask while the attacker is present is captured by the same standing behaviour, with no additional per-victim work. ## The catch on the cheap route: you must be there when they ask The lease route's weakness is timing, not effort. A host that has been up for three weeks is not asking anybody anything. It accepts a new answer only when it comes up, when it joins the segment, or when its existing lease is running down and it goes looking again. So an attacker with a two-hour window on a segment of long-uptime hosts may capture almost nothing, while the reply route works on those same hosts the moment it starts. Conversely an attacker who can stay for a day and a night collects the morning boot wave without doing anything else. The lease route also has to win: the legitimate server is answering too, and the host takes the first acceptable answer it gets. ## Which position survives what - **Host reboot.** The reply route's position evaporates - the cache is empty and the attacker must rebuild it. The lease route survives in a sense that matters: the host comes up and asks again, and if the attacker is still there it wins again; if the attacker has left, the host simply gets a real answer. - **The attacker unplugging.** The reply route fails silently and the victim recovers on its own. The lease route leaves a scar: the host keeps sending to a gateway and resolver that are no longer there, and it black-holes until it next asks. Cheaper to hold is not the same as quieter to abandon. - **A wired-to-wireless move.** Both are lost. The host acquires a new configuration on the new segment and the attacker no longer has adjacency to it. - **A switch reload.** Both positions are interrupted. The reply route must be re-driven from scratch; the configured hosts come back still pointing at the attacker. ## The judgment to show The right answer to "which would you use" is a question about the window, not a preference. Short window, hosts already running, one specific target: answer for the gateway's address and pay the rent. Long presence, several hosts, and the resolver is what you actually want: wait for the configuration requests and take the position for free. And the reason the comparison matters defensively is that the two positions are not equally durable or equally broad, so treating them as the same finding under one heading understates one of them.
- Why does answering for the gateway's address cost the attacker continuously while the lease route does not?The mapping being falsified is short-lived and constantly re-learned, so the false claim has to be re-asserted for as long as the position is wanted, in both directions and separately per victim. A configuration answer, by contrast, is written down by the host and used until it next asks, so the attacker pays once and can then stay silent.
- What does the lease route give an attacker that the reply route never does?The resolver. The same answer that sets the default gateway also sets what the host asks for name lookups, so the attacker decides where names point before any session is attempted. The reply route only puts the attacker on the path of traffic that has already been addressed somewhere.
- You have a two-hour authorised window on a segment whose hosts have been up for weeks. Which route?The reply route. The lease route only captures hosts at the moment they ask for configuration, and long-uptime machines are not asking. Two hours will not produce a boot wave, so the cheaper-to-hold position is unavailable and the immediate, rent-paying one is the only route that works in the window.
- Which route is louder to abandon, and why does that matter?The lease route. Hosts keep using a gateway and resolver that have gone away, so connectivity fails for them until they next ask, and the failure is visible to users. Abandoning the reply route is silent: the falsified mapping simply ages out and the victims recover with nobody noticing anything happened.
saying these in an interview costs you the question
- Treats the two routes as interchangeable ways to get on-path
- Forgets the lease route also installs the resolver
- Thinks a single forged reply holds the position indefinitely
- Claims the lease route works on demand against any running host
- Ignores that the reply route obliges the attacker to forward traffic