By default, dhcp clients will accept the first DHCPOFFER they receive.  If it comes from a rogue server, network functionality can be compromised.

0Steps to Correct

lease {
  interface "eth0";
  option subnet-mask;
  option routers;
  option dhcp-lease-time 86400;
  option dhcp-message-type 5;
  option domain-name-servers;
  option dhcp-server-identifier;
  option dhcp-renewal-time 43200;
  option dhcp-rebinding-time 75600;
  renew 5 2008/2/15 19:39:22;
  rebind 5 2008/2/15 19:39:22;
  expire 5 2008/2/15 19:39:22;

interface "eth0" {
  # block server by recognizing it provides no domain name, and the valid one does
  require domain-name;
  # block by server ip, except this will break the server at home
