How about this attack:

- Create a rogue DHCP server
- Allocate a block of normal IP addresses which are within the pool of the real DHCP server but not in use
- Send all the right info to the...