0 / 5
ARP Spoofing
An attacker on the same LAN wants to intercept the traffic between the victim PC and the gateway. On a LAN, a device must know the other side's MAC address before it can send data. The table that pairs IP addresses with MAC addresses is the ARP table, and the attacker tricks that table.
Example: When the victim PC goes online, every packet passes through the gateway.
1 / 5
The victim PC asks the whole LAN for the gateway's MAC address. Every device on the LAN receives the question, so the attacker sees it too.
2 / 5
The gateway replies with its own MAC address. The victim PC records the reply in its ARP table as a dynamic entry.
3 / 5
The attacker sends the victim PC a forged reply that says “the gateway's MAC address is the attacker's”. ARP has no way to check who sent a reply. Even if nobody asked, the victim PC overwrites the existing dynamic entry with the new value.
4 / 5
The attacker sends the gateway a forged reply too, saying “the victim PC's MAC address is the attacker's”. Now both sides send to the attacker instead of to each other.
5 / 5
Packets the victim PC sends to the gateway reach the attacker first. The attacker reads or changes them and then forwards them to the gateway, and the other direction works the same way. Because the traffic is forwarded, the connection does not break, and the victim is unlikely to notice.
1 / 4
An administrator enters the other side's real MAC address on both devices as a static entry, for example arp -s 192.168.0.1 02-00-00-00-00-01.
2 / 4
With a static entry in place, the victim PC does not need to ask the LAN for the gateway's MAC address. It sends right away.
3 / 4
Even when the attacker sends forged replies to both devices, the static entries do not change.
4 / 4
Packets go straight between the victim PC and the gateway without passing the attacker. If only one side has a static entry, the other direction can still be fooled, so register both sides.