PDA

View Full Version : Static ARP Table as defence against APR Poisoning



lovert
2023-09-01, 06:01
I am running Opnsense firewall. I have static ARP entries set to "required" and setup each client with DHCP / mac address filtering and ARP entry. I also have option for "deny unknown clients" DHCP.

Now I setup an ARP poisoning attack using Ettercap between 1 client and the firewall. The attack is successful.

On the client machine arp -a shows that the MAC address of the firewall changes to Ettercap's address however on the Opnsense box the MAC address of the client stays the same (ie is the real MAC of the client not the ettercap address).

So only the client needs the ARP poisoning to be successful ?

Fred Sheehan
2023-09-26, 17:38
At the ethernet layer, all addressing is done with MAC addresses, so 'spoofing' a MAC address can make any machine appear as another, thats the point...
You need to read up on the basics of networking..