
Serveur DHCP malveillant pour CVE-2026-9997 : injecte des routes statiques Option 121 dans les clients VPN, contournant le split tunneling pour exfiltrer le trafic sensible.
#!/usr/bin/env python3
# rogue_dhcp_server.py - Injects a static route to bypass VPN split tunnel
import socket, struct, threading
def send_dhcp_offer(client_mac, offer_ip):
# Craft a DHCP OFFER packet with Option 121 (Classless Static Route)
# This option adds a route that sends traffic to a sensitive subnet via the attacker's gateway.
# We'll simulate by creating a raw packet (simplified).
# In a real attack, we'd use scapy; here we just demonstrate the concept.
print(f"Sending DHCP OFFER to {client_mac} with malicious static route...")
# The client would then apply this route and leak traffic.
Un client VPN d'entreprise accepte les options DHCP (option 121 – routes statiques sans classe) provenant du réseau local sans validation. Un attaquant sur le même LAN peut injecter des routes qui envoient le trafic sensible hors du tunnel VPN chiffré.
python rogue_dhcp_server.py
python vpn_client_sim.py