DWS-3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide
941
Figure 4
Generally, the aim is to associate the attacker's or random MAC address with the IP address of
another node (such as the default gateway). Any traffic meant for that IP address would be
mistakenly re-directed to the node specified by the attacker.
IP spoofing attack is caused by Gratuitous ARP that occurs when a host sends an ARP request to
resolve its own IP address. Figure-4 shows a hacker within a LAN to initiate ARP spoofing attack.
In the Gratuitous ARP packet, the “Sender protocol address” and “Target protocol address” are
filled with the same source IP address itself. The “Sender H/W Address” and “Target H/W address”
are filled with the same source MAC address itself. The destination MAC address is the Ethernet
broadcast address (FF-FF-FF-FF-FF-FF). All nodes within the network will immediately update
their own ARP table in accordance with the sender’s MAC and IP address. The format of
Gratuitous ARP is displayed in the following table.
A common DoS attack today can be done by associating a nonexistent or any specified MAC
address to the IP address of the network’s default gateway. The malicious attacker only needs to
broadcast one Gratuitous ARP to the network claiming it is the gateway so that the whole network
operation will be turned down as all packets to the Internet will be directed to the wrong node.
Содержание DWS-3160-24TC
Страница 1: ......
Страница 13: ...DWS 3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide 9 R refresh the displayed pages ...
Страница 271: ...DWS 3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide 267 ...
Страница 586: ...DWS 3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide 582 ...
Страница 766: ...DWS 3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide 762 ...