What is it?
Dynamic Host Configuration Protocol is a network protocol used for assigning IP addresses and other network configuration parameters automatically to the networking devices on a network.
DHCP is based on a client-server model and uses UDP ports 67 (server) and 68 (client).
Significance of DHCP
Without an IP address, the client cannot establish a connection to the server.
Assigning IP addresses manually is tedious at the enterprise level. So DHCP plays an important role in networking.
DHCP allows devices to connect to a network and receive all necessary network information — like IP address, subnet mask, default gateway, and DNS server addresses — automatically from a DHCP server.
DORA Process
DORA stands for Discover, Offer, Request, Acknowledge. DHCP uses the DORA process to provide an IP address to hosts or client machines.
Discover Message:
This message is generated by the client host to discover whether any DHCP server(s) are present on the network. This message is broadcasted to all devices present in a network to find the DHCP server.
Offer Message:
The server responds to the host with this message, specifying an un-leased IP address and other network configuration information. This message is broadcasted by the server.
The client accepts the message from the DHCP server that responds first, if there are multiple DHCP servers.
Request Message:
When a client receives an offer message, it responds by broadcasting a DHCP request message. The client will generate a gratuitous ARP to check whether any other host on the network already has the same IP address. Up to this stage, the IP address is not yet confirmed.
Acknowledgement Message:
In response to the request message, the server makes an entry with the specified client ID and binds the offered IP address with a lease time. Now the client has the IP address provided by the server.
DHCP Starvation Attack
A DHCP starvation attack happens when a hacker floods a DHCP server with requests for IP addresses. This overwhelms the server, making it unable to assign addresses to legitimate users. The hacker can then block access for authorized users by exhausting the available addresses, and potentially set up a rogue DHCP server to intercept and manipulate network traffic — which could lead to a MITM attack.