I don't know why anyone would bother with ARP poisoning. Internal pentests are invariably bloodbaths; you spend 3 hours getting shells on 2-3 systems, and then another hour getting shells on 200-300 more as a result of all the stuff you find on those 3. On internal networks, the admin password is always "admin", the database password "oracle".