networking:dhcp_find_rogue
This is an old revision of the document!
Find a Rogue DHCP Server
DHCP Process
DORA
Discover
Offer
Request
Acknowledge
Capture the Process
Note the IP address of valid
DHCP server
See
DHCP Release packet from working client
Start Wireshark
ipconfig /release
ipconfig /renew
Save the capture
Analyze the Capture
In Wireshark:
Open the .pcap
file
Filter on bootp
packets
Filter on bootp.option.dhcp == 2
packets
networking/dhcp_find_rogue.1532111628.txt.gz · Last modified: 2018/07/20 12:33 by gcooper