skip to content

Claimed Names and Addresses

Nothing on a segment checks who answers for a name or owns an address, so a forged ARP reply, a rogue DHCP offer or the first LLMNR answer is believed. Interviewers test the protocol underneath.

on this pageshow

explore

questions

20

On a flat office VLAN, why does becoming a host's gateway need no account or exploit?

level: juniorimportance: must knowfreq 66%

answer

  1. who told the host where to send packets
  2. neither answer is authenticated
  3. first acceptable answer wins
  4. no defect, so no patch level helps
  5. cost of entry is a cable, not a credential

basics

~20 s

Nothing authenticates the answers. A host takes its gateway and resolver from whichever lease answer arrives first, and locates that gateway from whoever replies for its address. Adjacency to the segment is the only prerequisite: no credential, no software flaw.

solid answer

~50 s

A host that comes up on a wall port knows nothing about how to leave the segment. It is told: a lease answer hands it an address, a default gateway and a resolver, and it then finds the gateway's hardware address by asking the segment and believing the reply. Neither of those answers is authenticated - there is no secret between client and lease server, no signature, no list of servers a client will accept, and no check that the machine replying for the gateway address is the gateway. So an attacker needs standing on the wire and nothing else: no directory account, no exploited service, no privilege anywhere. That is why "we are fully patched" is not a defence. Patching removes implementation defects; here the protocols are behaving exactly as specified, and there is no advisory or version that changes it.

go deeper

for a junior

Be ready to say plainly what a host has to be told before it can send anything off-segment, and that nothing checks who told it. Naming adjacency as the only prerequisite is the answer an interviewer is listening for.

for a middle

Expect to be pushed on the difference between an implementation defect and design trust, and to explain why no patch level or hardened image touches the second. Be able to describe both answers a host relies on without hand-waving.

for a senior

Show that you can price the exposure rather than describe it: which hosts on a mixed office segment actually matter, what a visitor with a wall port can reach, and why the honest fix is structural rather than a version bump.

for a principal

Own the framing when someone reports this as a finding with no CVE attached. Be able to explain to a risk owner why an unpatchable design property is a legitimate entry on the register, and what class of change - not which product - retires it.

## What a host has to be told, and who tells it Nothing on a plain office VLAN is born knowing how to leave it. A machine that has just come up on a conference-room wall port knows only what it is handed. It asks the segment for configuration and takes, from the answer it gets, three things that matter: an address of its own, the address of a **default gateway** (where it sends anything not on the local segment), and the address of a **resolver** (what it asks to turn names into addresses). Having been told which address is the gateway, it still has to reach that address on the wire, so it asks the segment which hardware address owns it and uses whatever comes back. Two answers therefore decide where every packet the host sends actually goes. Neither is authenticated in any meaningful sense. There is no shared secret between a client and whatever answered its configuration request, no signature over the answer, no list of servers the client is willing to believe, and no verification that the machine replying on behalf of the gateway address is the gateway. The client applies a first-acceptable-answer rule and gets on with its work. That is not a bug anybody shipped; it is what makes plug-in-and-it-works possible. ## Why "we are fully patched" is not an answer The reflex when a network attack is described is to ask which version fixes it. Nothing does. There is no defect being triggered here - no memory corruption, no missing bounds check, no unauthenticated management endpoint. An attacker taking the first-hop position sends well-formed messages that every implementation on that segment is required to accept, and the hosts do exactly what their documentation says they will do. So there is no identifier to look up, no advisory to read and no patch level that changes the exposure. A fully current, hardened, signed-image fleet on a flat segment is exposed in precisely the same way as an unpatched one. This matters in interviews because it separates two categories a candidate must not conflate: **implementation vulnerabilities**, which are mistakes and get fixed, and **design trust**, which is a property of the environment and gets removed only by changing the environment - who is allowed to speak on the segment at all, and whether the hosts that matter share one. That structural answer is a separate subject; the point here is only that patching is not it. ## The adversary class this creates The interesting consequence is the kind of attacker it admits. Most intrusion stories start with a credential: somebody is phished, a password is reused, a token is stolen. This one starts with a cable. Consider a vendor engineer on site to service a badge controller. They have no directory account, cannot log in to anything, are not authorised to touch a server, and would fail every access check in the building - and they have a laptop and a live switch port in a room they were shown to. Physical standing, zero logical rights. That combination is enough, because the only prerequisite the position has is link-layer adjacency. The same is true of anyone else who gets a port: a contractor, a visitor left alone in a meeting room, a device plugged into a wall socket behind a plant. It is also true of a machine that was already compromised for other reasons, which now has adjacency for free. ## Why the flat mixed segment makes it worse Office VLANs are rarely just laptops. The same broadcast domain typically carries printers, badge readers, IP cameras and other fixed-function devices. Those endpoints have no ability to be sceptical: they take the configuration they are given, many of them never encrypt anything they send, and several authenticate nothing at either end. So the value of the position is not bounded by what the laptops are doing. The segment is only as trustworthy as its least controlled port, and a conference-room port is by definition available to people you did not vet. ## Two routes, priced differently There is more than one way to occupy the position - you can answer for the gateway's hardware address, or you can be the one who answers the configuration request in the first place. They are not equivalent: they hand over different things, cost different amounts to hold, and survive different events. Pricing them against each other is the real senior question here. But both start from the same place, and the thing to be able to say cleanly in an interview is that the starting cost is adjacency, and adjacency is not a vulnerability anyone can patch away.

  • The fleet is fully patched and runs signed OS images. Does any of that change the exposure?
    No. Patching and image integrity address defects in code that runs on the host. Here nothing defective runs: the host receives a well-formed answer and honours it, exactly as specified. There is no advisory, no fixed version and no identifier to track. The exposure changes only when the segment changes - who may speak on it, and which hosts share it.
  • Once an attacker holds the first-hop position, what have they actually gained at that moment?
    Traffic leaving the affected hosts passes through them, so they choose whether it is forwarded, delayed or dropped. If they became the position by answering the configuration request rather than by answering for the gateway's hardware address, they were also installed as the host's resolver, which means they influence where sessions go before any session exists.
  • Why does a segment shared with printers, badge readers and cameras raise the stakes?
    Those devices accept whatever configuration they are handed, frequently send in the clear, and often authenticate nothing at either end. So the position is not limited to what a laptop's encrypted sessions leak; a print job, a door event or a camera stream on the same broadcast domain can be plainly available to whoever sits in front of them.

It is like a reception desk that gives directions to anyone who walks up and asks, and a visitor who follows whoever answers first. Nobody is lying about their badge, because nobody was ever asked for one.

saying these in an interview costs you the question

  • Claims the attacker needs valid domain credentials first
  • Says a fully patched fleet is not exposed
  • Treats it as a vulnerability with a CVE and a fixed version
  • Assumes only wireless or guest networks are affected
  • Thinks the switch would refuse an unauthorised answer by default

context

open as a page

In an IP packet, what does the source address field actually prove about the sender?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Nothing on its own. The source address is chosen by whoever builds the packet, and nothing along the path verifies it, because routers forward on the destination. It proves a value was written, not who wrote it.

open as a page

Why can't an off-path attacker just send a forged DNS reply to a recursive resolver?

level: juniorimportance: must knowfreq 64%

basics

~20 s

The resolver only accepts a reply that matches its outstanding query: same server address and port, same ephemeral port it asked from, same 16-bit message ID, same question. And it must arrive before the genuine answer.

open as a page

What is a dangling DNS record, and how does it hand your subdomain to a stranger?

level: juniorimportance: must knowfreq 55%

basics

~20 s

A dangling DNS record still resolves to a target that is no longer yours: a released storage bucket, app slot or cancelled vendor tenant. Whoever re-registers that target name is then served under your subdomain.

open as a page

ARP replies or a rogue DHCP lease: which route to a host's first hop costs less to hold?

level: middleimportance: must knowfreq 57%

basics

~20 s

The lease route is far cheaper. One answer installs the attacker as gateway and resolver for that host and then needs no upkeep. Answering for the gateway's address covers one victim at a time and must be re-asserted continuously, forever.

open as a page

What does a client verify about the host that answers its LLMNR or NBT-NS query?

level: middleimportance: must knowfreq 60%

basics

~20 s

Nothing meaningful. LLMNR, NBT-NS and mDNS carry no authentication, no signature and no record of who owns a name, so the client accepts the first well-formed reply matching its query. Whoever answers fastest on the link owns the name.

open as a page

Why is a source-IP allowlist on a UDP control service not an authentication control?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Because the value it checks is written by the sender. Over UDP the effect lands when the datagram arrives, so a forger never needs the reply. The allowlist constrains honest traffic and stops nobody willing to lie.

open as a page

Why does a Windows host broadcast an LLMNR or NBT-NS query after DNS returns NXDOMAIN?

level: juniorimportance: should knowfreq 46%

basics

~20 s

Windows treats name resolution as a chain, not one authority. NXDOMAIN ends only the DNS step; the host then asks every machine on its own link over LLMNR and NBT-NS, and accepts the first reply it gets.

open as a page

What can an attacker accomplish with a forged source address when no reply ever comes back?

level: middleimportance: should knowfreq 52%

basics

~10 s

Only attacks whose effect lands on arrival: single-datagram commands, floods that consume state at the target, and provoking a third party into answering the forged address. Anything needing something back is out of reach.

open as a page

How much entropy must an off-path DNS forger beat inside one query's lifetime?

level: middleimportance: should knowfreq 47%

basics

~10 s

Roughly 2^30 to 2^32: a 16-bit message ID times 14 to 16 bits of ephemeral-port randomisation, all inside one round-trip. A gigabit of forgeries buys odds near one in tens of thousands per race.

open as a page

Why is a subdomain takeover more than a DNS hygiene ticket when no defect was exploited?

level: middleimportance: should knowfreq 48%

basics

~20 s

Because the asset handed over is the organisation's own name, not the dead resource. A held subdomain inherits cookies scoped to the parent domain, any trust granted by name suffix, certificate eligibility for that host, and the name's reputation.

open as a page

"Everything is TLS now" - what is a first-hop position on a flat office VLAN still worth?

level: seniorimportance: should knowfreq 48%

basics

~20 s

Plenty. Encryption protects session content, but the first hop sits underneath it: it decides which names resolve and to what, denies upgrades to protocols that start in the clear, drops selectively, and sees the printers and cameras that never encrypt.

open as a page

Why is calling an LLMNR name-answer attack 'DNS cache poisoning' the wrong classification?

level: seniorimportance: should knowfreq 38%

basics

~10 s

No DNS message was forged and no cache was altered. The DNS server truthfully said the name does not exist; the client then used a different protocol that has no authority at all.

open as a page

Told that source-port randomisation makes DNS cache poisoning infeasible, how do you answer?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Concede the arithmetic, reject the conclusion. The objective is to be believed as the authority for a name, and that is on sale far cheaper at the registrar, where changing the delegation beats no entropy.

open as a page

Subdomain takeover needs a resolving name and a claimable target — which do you remove, and in what order?

level: seniorimportance: should knowfreq 38%

basics

~10 s

Remove either and the attack dies, so remove both: retire the record before releasing the resource, and prefer targets bound to proven domain ownership. Patching removes neither dependency.

open as a page

Your staging DHCP server sits on the office VLAN: how does a client tell its lease from a rogue's?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

It cannot. A client validates no server identity and takes the first acceptable answer, so a misplaced staging server and a hostile one are identical on the wire. Rogue is a claim about ownership, not about the packets.

open as a page

Why is winning the WPAD name lookup worth more than winning a mistyped file-share name?

level: seniorimportance: nice to knowfreq 26%

basics

~10 s

A typo wins one connection from one host by accident. WPAD is asked for automatically by many hosts, and its answer is a configuration URL deciding where web traffic goes.

open as a page

As a hosting provider, how do you justify funding source-address validation that protects other networks?

level: principalimportance: nice to knowfreq 30%

basics

~10 s

Stop arguing it on altruism and name what you capture: your address space's reputation, recurring abuse-handling cost, peer and contract pressure, and the customer-to-customer forgery the same validation stops inside your own estate.

open as a page

Your registrar account for every company domain sits with marketing — what do you require, and how do you win it?

level: principalimportance: nice to knowfreq 27%

basics

~10 s

Treat the registrar account as a root of trust: registry-level change locks on load-bearing domains, phishing-resistant sign-in, a company-controlled recovery address, two-person approval. Win it by buying marketing a fast approval path.

open as a page

Your DNS zone sits with one team and cloud resources with dozens — who is accountable for names that outlive their targets?

level: principalimportance: nice to knowfreq 22%

basics

~20 s

Accountability belongs with whoever creates the record, enforced by making the record part of the resource's lifecycle. A central zone team can gate and expire records but cannot know when a resource dies, so pure centralisation fails.

open as a page