A packet capture reveals unsolicited ARP replies mapping an unknown MAC address to the network gateway IP, followed by unencrypted HTTP requests containing a session cookie. The application enforces HTTPS but loads HTTP images. Which attack occurred?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ANothing in the capture points to forged DNS answers, and the cookie leaked through cleartext HTTP rather than through a script injected into the page.
- BThe unsolicited ARP replies do fit ARP spoofing, but CSRF makes the victim's browser send forged requests and never discloses the session cookie to the attacker.
- CMAC flooding fills a switch's address table with bogus entries, which looks different from targeted ARP replies claiming the gateway's IP address.
- DCorrect: Spoofed ARP replies put the attacker in the path, and HTTP-loaded images let a cookie without the Secure attribute travel in cleartext; HSTS and the Secure flag prevent this.