Talk With an Expert

Finding dsniff on Your Network

Finding dsniff on Your Network (PDF, 1.83MB)Published: 28 Nov, 2001
Created by:
Richard Duffy

This paper covers some ways to detect dsniff and two of its utilities, arpspoof and macof, on a network. Arpspoof and macof tools were used with dsniff to determine if dsniff could be detected. The following programs were used to detect various aspects of dsniff: Arpwatch, ZoneAlarm, Antisniff and tcpdump. Our existing Fluke network test equipment was connected to the network to evaluate what indicators each could provide about dsniff and its tools.