skip to content

Network and Protocol Attacks

You will learn how an attacker becomes the first hop, poisons a name, rides a session already open, or takes the path away. Interviewers use these to test whether you know the protocol underneath.

on this pageshow

explore

questions

page 1 of 2

On a flat office VLAN, why does becoming a host's gateway need no account or exploit?

level: juniorimportance: must knowfreq 66%

answer

  1. who told the host where to send packets
  2. neither answer is authenticated
  3. first acceptable answer wins
  4. no defect, so no patch level helps
  5. cost of entry is a cable, not a credential

basics

~20 s

Nothing authenticates the answers. A host takes its gateway and resolver from whichever lease answer arrives first, and locates that gateway from whoever replies for its address. Adjacency to the segment is the only prerequisite: no credential, no software flaw.

solid answer

~50 s

A host that comes up on a wall port knows nothing about how to leave the segment. It is told: a lease answer hands it an address, a default gateway and a resolver, and it then finds the gateway's hardware address by asking the segment and believing the reply. Neither of those answers is authenticated - there is no secret between client and lease server, no signature, no list of servers a client will accept, and no check that the machine replying for the gateway address is the gateway. So an attacker needs standing on the wire and nothing else: no directory account, no exploited service, no privilege anywhere. That is why "we are fully patched" is not a defence. Patching removes implementation defects; here the protocols are behaving exactly as specified, and there is no advisory or version that changes it.

go deeper

for a junior

Be ready to say plainly what a host has to be told before it can send anything off-segment, and that nothing checks who told it. Naming adjacency as the only prerequisite is the answer an interviewer is listening for.

for a middle

Expect to be pushed on the difference between an implementation defect and design trust, and to explain why no patch level or hardened image touches the second. Be able to describe both answers a host relies on without hand-waving.

for a senior

Show that you can price the exposure rather than describe it: which hosts on a mixed office segment actually matter, what a visitor with a wall port can reach, and why the honest fix is structural rather than a version bump.

for a principal

Own the framing when someone reports this as a finding with no CVE attached. Be able to explain to a risk owner why an unpatchable design property is a legitimate entry on the register, and what class of change - not which product - retires it.

## What a host has to be told, and who tells it Nothing on a plain office VLAN is born knowing how to leave it. A machine that has just come up on a conference-room wall port knows only what it is handed. It asks the segment for configuration and takes, from the answer it gets, three things that matter: an address of its own, the address of a **default gateway** (where it sends anything not on the local segment), and the address of a **resolver** (what it asks to turn names into addresses). Having been told which address is the gateway, it still has to reach that address on the wire, so it asks the segment which hardware address owns it and uses whatever comes back. Two answers therefore decide where every packet the host sends actually goes. Neither is authenticated in any meaningful sense. There is no shared secret between a client and whatever answered its configuration request, no signature over the answer, no list of servers the client is willing to believe, and no verification that the machine replying on behalf of the gateway address is the gateway. The client applies a first-acceptable-answer rule and gets on with its work. That is not a bug anybody shipped; it is what makes plug-in-and-it-works possible. ## Why "we are fully patched" is not an answer The reflex when a network attack is described is to ask which version fixes it. Nothing does. There is no defect being triggered here - no memory corruption, no missing bounds check, no unauthenticated management endpoint. An attacker taking the first-hop position sends well-formed messages that every implementation on that segment is required to accept, and the hosts do exactly what their documentation says they will do. So there is no identifier to look up, no advisory to read and no patch level that changes the exposure. A fully current, hardened, signed-image fleet on a flat segment is exposed in precisely the same way as an unpatched one. This matters in interviews because it separates two categories a candidate must not conflate: **implementation vulnerabilities**, which are mistakes and get fixed, and **design trust**, which is a property of the environment and gets removed only by changing the environment - who is allowed to speak on the segment at all, and whether the hosts that matter share one. That structural answer is a separate subject; the point here is only that patching is not it. ## The adversary class this creates The interesting consequence is the kind of attacker it admits. Most intrusion stories start with a credential: somebody is phished, a password is reused, a token is stolen. This one starts with a cable. Consider a vendor engineer on site to service a badge controller. They have no directory account, cannot log in to anything, are not authorised to touch a server, and would fail every access check in the building - and they have a laptop and a live switch port in a room they were shown to. Physical standing, zero logical rights. That combination is enough, because the only prerequisite the position has is link-layer adjacency. The same is true of anyone else who gets a port: a contractor, a visitor left alone in a meeting room, a device plugged into a wall socket behind a plant. It is also true of a machine that was already compromised for other reasons, which now has adjacency for free. ## Why the flat mixed segment makes it worse Office VLANs are rarely just laptops. The same broadcast domain typically carries printers, badge readers, IP cameras and other fixed-function devices. Those endpoints have no ability to be sceptical: they take the configuration they are given, many of them never encrypt anything they send, and several authenticate nothing at either end. So the value of the position is not bounded by what the laptops are doing. The segment is only as trustworthy as its least controlled port, and a conference-room port is by definition available to people you did not vet. ## Two routes, priced differently There is more than one way to occupy the position - you can answer for the gateway's hardware address, or you can be the one who answers the configuration request in the first place. They are not equivalent: they hand over different things, cost different amounts to hold, and survive different events. Pricing them against each other is the real senior question here. But both start from the same place, and the thing to be able to say cleanly in an interview is that the starting cost is adjacency, and adjacency is not a vulnerability anyone can patch away.

  • The fleet is fully patched and runs signed OS images. Does any of that change the exposure?
    No. Patching and image integrity address defects in code that runs on the host. Here nothing defective runs: the host receives a well-formed answer and honours it, exactly as specified. There is no advisory, no fixed version and no identifier to track. The exposure changes only when the segment changes - who may speak on it, and which hosts share it.
  • Once an attacker holds the first-hop position, what have they actually gained at that moment?
    Traffic leaving the affected hosts passes through them, so they choose whether it is forwarded, delayed or dropped. If they became the position by answering the configuration request rather than by answering for the gateway's hardware address, they were also installed as the host's resolver, which means they influence where sessions go before any session exists.
  • Why does a segment shared with printers, badge readers and cameras raise the stakes?
    Those devices accept whatever configuration they are handed, frequently send in the clear, and often authenticate nothing at either end. So the position is not limited to what a laptop's encrypted sessions leak; a print job, a door event or a camera stream on the same broadcast domain can be plainly available to whoever sits in front of them.

It is like a reception desk that gives directions to anyone who walks up and asks, and a visitor who follows whoever answers first. Nobody is lying about their badge, because nobody was ever asked for one.

saying these in an interview costs you the question

  • Claims the attacker needs valid domain credentials first
  • Says a fully patched fleet is not exposed
  • Treats it as a vulnerability with a CVE and a fixed version
  • Assumes only wireless or guest networks are affected
  • Thinks the switch would refuse an unauthorised answer by default

context

open as a page

In an IP packet, what does the source address field actually prove about the sender?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Nothing on its own. The source address is chosen by whoever builds the packet, and nothing along the path verifies it, because routers forward on the destination. It proves a value was written, not who wrote it.

open as a page

Why can't an off-path attacker just send a forged DNS reply to a recursive resolver?

level: juniorimportance: must knowfreq 64%

basics

~20 s

The resolver only accepts a reply that matches its outstanding query: same server address and port, same ephemeral port it asked from, same 16-bit message ID, same question. And it must arrive before the genuine answer.

open as a page

What is a dangling DNS record, and how does it hand your subdomain to a stranger?

level: juniorimportance: must knowfreq 55%

basics

~20 s

A dangling DNS record still resolves to a target that is no longer yours: a released storage bucket, app slot or cancelled vendor tenant. Whoever re-registers that target name is then served under your subdomain.

open as a page

What does the amplification factor measure in a reflection attack, and how do you compute it?

level: juniorimportance: must knowfreq 65%

basics

~20 s

The amplification factor is the ratio of response bytes reaching the victim to request bytes the attacker spent. A 62-byte request drawing a 3,000-byte answer runs at roughly 48x, so a small uplink delivers a large flood.

open as a page

A partner's signed, TLS-protected payment instruction is captured and sent twice — why does the second copy pay?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Signing proves who composed the message and that nobody altered it; encryption hides it from others. Neither says this copy is the first. Only receiver-held state — a counter, remembered identifier or time window — refuses a duplicate.

open as a page

What does a live session cookie prove about who is at the keyboard right now?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Only that the sender holds a value the service issued earlier and has not expired. The factors were checked once, at issuance; every later request is honoured on possession alone. A session proves acceptance in the past, not presence now.

open as a page

ARP replies or a rogue DHCP lease: which route to a host's first hop costs less to hold?

level: middleimportance: must knowfreq 57%

basics

~20 s

The lease route is far cheaper. One answer installs the attacker as gateway and resolver for that host and then needs no upkeep. Answering for the gateway's address covers one victim at a time and must be re-asserted continuously, forever.

open as a page

What does a client verify about the host that answers its LLMNR or NBT-NS query?

level: middleimportance: must knowfreq 60%

basics

~20 s

Nothing meaningful. LLMNR, NBT-NS and mDNS carry no authentication, no signature and no record of who owns a name, so the client accepts the first well-formed reply matching its query. Whoever answers fastest on the link owns the name.

open as a page

For flood capacity, why rent 100,000 consumer devices over eight high-bandwidth hosts?

level: middleimportance: must knowfreq 60%

basics

~20 s

Because they are different products. Eight fat hosts sell throughput. A hundred thousand consumer addresses sell source diversity: traffic spread across thousands of networks, each flow indistinguishable from an ordinary customer, that no single coarse decision removes.

open as a page

Which two properties make a network protocol usable as a reflection amplifier?

level: middleimportance: must knowfreq 55%

basics

~10 s

Connectionless carriage, so one arriving datagram is enough to commit a full answer, and no check that the address being answered is the address that asked. A bulky request/response pair then supplies the ratio.

open as a page

How do a monotonic counter, a remembered-message-id set and a clock window differ in what the receiver must keep?

level: middleimportance: must knowfreq 54%

basics

~20 s

A counter stores one number per sender but needs ordered delivery and must survive restarts. An identifier set tolerates disorder but needs storage and a retention bound. A clock window needs synchronised clocks and, alone, still permits replay inside it.

open as a page

Why doesn't TCP's 32-bit sequence space make blind injection into an established flow infeasible?

level: middleimportance: must knowfreq 58%

basics

~20 s

Because the receiver does not demand one exact value. Any sequence number falling inside the advertised receive window is acceptable, so the real search is the sequence space divided by the window - thousands of guesses on a high-throughput link, not billions.

open as a page

Why does a renewing session survive a policy that demands MFA at every login?

level: middleimportance: must knowfreq 66%

basics

~20 s

Because the policy gates logins, and a renewing session never produces another one. Idle timers restart on every request and refresh credentials mint fresh tokens with no ceremony, so the login that would demand the factor may never arrive.

open as a page

Why is a source-IP allowlist on a UDP control service not an authentication control?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Because the value it checks is written by the sender. Over UDP the effect lands when the datagram arrives, so a forger never needs the reply. The allowlist constrains honest traffic and stops nobody willing to lie.

open as a page

'Just buy more bandwidth' - which of a web estate's exhaustible resources does that actually relieve?

level: seniorimportance: must knowfreq 47%

basics

~20 s

Only a saturated link. Bigger connection tables and worker pools add slots an attacker occupies almost free, and extra workers push more concurrent calls into the one slow dependency, whose capacity is usually not yours to buy.

open as a page

Why does a Windows host broadcast an LLMNR or NBT-NS query after DNS returns NXDOMAIN?

level: juniorimportance: should knowfreq 46%

basics

~20 s

Windows treats name resolution as a chain, not one authority. NXDOMAIN ends only the DNS step; the host then asks every machine on its own link over LLMNR and NBT-NS, and accepts the first reply it gets.

open as a page

In a for-hire DDoS attack, what does the buyer actually have to compromise?

level: juniorimportance: should knowfreq 58%

basics

~20 s

Nothing. Flood capacity is a commodity: the buyer rents time on a fleet someone else built, supplies a target and a duration, and never touches a host. The volume that arrives says nothing about the buyer's skill.

open as a page

Why is a weeks-long BGP peering session a better target for blind spoofed-segment injection than a short web connection?

level: juniorimportance: should knowfreq 42%

basics

~20 s

Time and predictability. The peering session stays up for weeks, so thousands of spoofed guesses can be tried against it, and both router addresses plus TCP port 179 are public, leaving far less of the connection identity to guess.

open as a page

What can an attacker accomplish with a forged source address when no reply ever comes back?

level: middleimportance: should knowfreq 52%

basics

~10 s

Only attacks whose effect lands on arrival: single-datagram commands, floods that consume state at the target, and provoking a third party into answering the forged address. Anything needing something back is out of reach.

open as a page

How much entropy must an off-path DNS forger beat inside one query's lifetime?

level: middleimportance: should knowfreq 47%

basics

~10 s

Roughly 2^30 to 2^32: a 16-bit message ID times 14 to 16 bits of ephemeral-port randomisation, all inside one round-trip. A gigabit of forgeries buys odds near one in tens of thousands per race.

open as a page

Why is a subdomain takeover more than a DNS hygiene ticket when no defect was exploited?

level: middleimportance: should knowfreq 48%

basics

~20 s

Because the asset handed over is the organisation's own name, not the dead resource. A held subdomain inherits cookies scoped to the parent domain, any trust granted by name suffix, certificate eligibility for that host, and the name's reputation.

open as a page

Why can a few thousand trickle-fed requests exhaust a web tier at almost no cost to the attacker?

level: middleimportance: should knowfreq 54%

basics

~20 s

Rank attacks by what the attacker keeps committed per unit of your capacity. A request dribbled out over minutes costs them one socket and a few bytes; it costs you a connection entry and a pinned worker throughout.

open as a page

Your receiver dedupes on an unsigned request-id header while the signature covers only the body — what replay is still possible?

level: middleimportance: should knowfreq 42%

basics

~20 s

The header sits outside the signed bytes, so whoever holds the message changes that value and resends the identical body. The deduplication key never matches, the signature still verifies, and the instruction executes again. The key must live inside the signed content.

open as a page

"Everything is TLS now" - what is a first-hop position on a flat office VLAN still worth?

level: seniorimportance: should knowfreq 48%

basics

~20 s

Plenty. Encryption protects session content, but the first hop sits underneath it: it decides which names resolve and to what, denies upgrades to protocols that start in the clear, drops selectively, and sees the printers and cameras that never encrypt.

open as a page

Why is calling an LLMNR name-answer attack 'DNS cache poisoning' the wrong classification?

level: seniorimportance: should knowfreq 38%

basics

~10 s

No DNS message was forged and no cache was altered. The DNS server truthfully said the name does not exist; the client then used a different protocol that has no authority at all.

open as a page

Told that source-port randomisation makes DNS cache poisoning infeasible, how do you answer?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Concede the arithmetic, reject the conclusion. The objective is to be believed as the authority for a name, and that is on sale far cheaper at the registrar, where changing the delegation beats no entropy.

open as a page

Subdomain takeover needs a resolving name and a claimable target — which do you remove, and in what order?

level: seniorimportance: should knowfreq 38%

basics

~10 s

Remove either and the attack dies, so remove both: retire the record before releasing the resource, and prefer targets bound to proven domain ownership. Patching removes neither dependency.

open as a page

A 90 Gbps flood came from six instances in an unrelated company's cloud account. How?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Stolen control-plane credentials. Someone used another organisation's cloud API access to launch a handful of very large instances aimed at the target, so capacity appeared in minutes, cost the attacker nothing, and was billed to the account owner.

open as a page

showing 1–30 of 44