    Like a lot of IT departments, the company I work for has an allow list of IP addresses to control who can access certain resources in our infrastructure.
    But how possible is it for an attacker to get their computer to assume one of those IP addresses and get access to all the stuff we’ve put that access control in for?

    You have to get into the network first. You can’t just assign your computer an IP address and access their data. You can do BGP hijacking, but that is going to get noticed.

    If it’s a public IPv4 address, then no.

    You can spoof your IP just by changing the packets

    You do have to be in the same subnet, a networking thing, but you can always just try setting the IP address manually. If your computer has the same three octets as your target it might work, especially if the other computer is not online. Otherwise, it gets complicated.

