Why an address is a claim, not a proof

The victim and the attacker sit on the same switched segment. Step through each scenario and watch two things only: the victim's ARP cache, and the address fields the sender wrote into the packet.

Network topology A trusted web server on the internet side, a router at the boundary, and a switch on the local LAN connecting the victim PC and the hacker PC. Internet side Local LAN, inside the firewall Trusted server 18.7.22.59 MAC never seen Router 192.168.1.1 Switch forwards frames Victim PC 192.168.1.100 00-b0-95-38-0a Hacker PC 192.168.1.102 00-a0-d2-14-a2-11 frame

Victim ARP cache

AddressResolves to
192.168.1.100-1a-2b-3c-4d-5e
192.168.1.10200-a0-d2-14-a2-11
18.7.22.59off LAN, no entry

Address fields on the wire

FieldValue asserted
source MAC-
dest MAC-
source IP-
dest IP-

Step 0

Choose a scenario, then press next step.

Arrow keys also work

What to take from this scenario

Why perimeter controls do not help

All of the LAN traffic above passes between two hosts on the same switch. It never crosses the router, so the firewall and NAT translation on the WAN interface never inspect it. The attacker is already inside the trust boundary, which is why the controls that matter here live on the switch and in the application: