Ethernet switches route by MAC address, not IP. When your host knows 192.168.1.1 is on the local subnet but not its MAC, it broadcasts an ARP request: "who has 192.168.1.1?"
ARP Packet Layout (28 Bytes)
Field
Value for Request
Hardware type
1 (Ethernet)
Protocol type
0x0800 (IPv4)
HW addr len
6
Proto addr len
4
Opcode
1 (request), 2 (reply)
Sender MAC/IP
your interface
Target MAC
00:00:00:00:00:00 (unknown)
Target IP
192.168.1.1
The Ethernet frame wraps this with destination ff:ff:ff:ff:ff:ff (broadcast), your source MAC, and EtherType 0x0806.
Sending with Raw Sockets
On Linux, AF_PACKET + SOCK_RAW lets you inject layer-2 frames directly:
c
Loading…
Because ARP sits below IP, you must build the Ethernet header yourself. Only the host owning the target IP unicasts a reply back to your MAC.
Why This Exercise
This task asks you to document ARP request construction with all fields printed. RFC 826 defines exactly this 28-byte layout, and the lack of authentication in ARP is why tools like arpspoof can poison caches with forged replies.
Implement a C program that assembles a full ARP request Ethernet frame from stdin parameters.
Input (stdin, whitespace-separated):
sender MAC as 12 hex characters (e.g. aabbccddeeff)
Build the 28-byte ARP payload per RFC 826: hardware type 1 (Ethernet), protocol type 0x0800 (IPv4), hardware address length 6, protocol address length 4, operation 1 (request), sender MAC, sender IP, target MAC 00:00:00:00:00:00 (unknown: it is what the request asks for), target IP
Print the field summary lines and the full 42-byte frame hex dump exactly as specified
Output format:
Line 1: ethertype=0x0806 opcode=1 request
Line 2: sender_mac=xx:xx:xx:xx:xx:xx sender_ip=N.N.N.N (colon-separated MAC, lowercase)
Line 3: target_mac=00:00:00:00:00:00 target_ip=N.N.N.N
Line 4: the complete 42-byte frame as two-digit lowercase hex, space-separated, prefixed with "hex="