Open cardosec

Case B766DA · Network · L2 Practitioner

ARP Spoofing

Practise as: Explain it · Interview

Interview questionHow does ARP spoofing enable a man-in-the-middle attack on a LAN, and how do you stop it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. ARP maps IPv4 to MAC with no authentication; hosts accept unsolicited (gratuitous) replies and update caches
  2. Attacker poisons victim and gateway caches with its own MAC, then forwards traffic to sit in the middle
  3. Enables sniffing, session hijacking, and SSL stripping of non-HSTS sites; tools include arpspoof, Bettercap
  4. Defense: Dynamic ARP Inspection validating against DHCP snooping bindings on managed switches
  5. Detect via duplicate MAC for gateway IP, arpwatch alerts; encryption (TLS, SMB signing) limits the impact

If the interviewer pushes back

  • What is the IPv6 equivalent of this attack, and which switch features defend against it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.