Javier Jarava wrote:
Hi all!

Just wondering, is there a way to "prevent" a rogue DCHP server from playing
havoc with a network?

I have been digging into "dhcp security" but I haven't really found anything
that makes it possible to auth. a DHCP server, so that the clients don't
fall for a rogue one.

I wrote a paper on this (and put the slides for a presentation I did on it online). At the time (and still, apart from what I've stuck online), there doesn't seem to be any definitive guide to why DHCP is insecure and what one might do to improve it. It's not totally exhaustive, but I think it's reasonable:

http://www.jeremiad.org/download.shtml

Hope that helps! Feedback welcome, if anyone reads it ;)

 - James.

--
  James (njan) Eaton-Lee | UIN: 10807960 | http://www.jeremiad.org

  "The universe is run by the complex interweaving of three
  elements: Energy, matter, and enlightened self-interest." - G'Kar

 https://www.bsrf.org.uk | ca: https://www.cacert.org/index.php?id=3
--

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to