DHCP leases exhaustion attack?

Randall C Grimshaw rgrimsha at syr.edu
Fri Sep 12 18:15:21 UTC 2008


one-lease-per-client true;

deny duplicates;

 

________________________________

From: dhcp-users-bounce at isc.org [mailto:dhcp-users-bounce at isc.org] On
Behalf Of schilling
Sent: Friday, September 12, 2008 1:43 PM
To: dhcp-users at isc.org
Subject: DHCP leases exhaustion attack?

 

Hi All,

We had a case that one MAC address obtained about 100 IP address from
our DHCP server in a short time period. We noticed that some DHCP
requests come with different Windows Netbios name. If the client
manually send DHCP request asking for different IP addresses, will ISC
DHCPD just give to them without checking the current lease file that the
same MAC already has a lease? Or will ISC DHCPD has a option to limit
how many IP could be associated with a MAC?

I saw Yersinia tool can send DHCP request, but I did not try it out yet.
Will that tool hack the DHCP server similar to our case?

Thanks.

Schilling

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/dhcp-users/attachments/20080912/3838f7c8/attachment.html>


More information about the dhcp-users mailing list