Andrew Mercer
on this page

dsniff is a classic collection of network auditing and interception tools. It is included here so you can recognise what they do and defend against them. Use them only on networks you own or are explicitly authorised to test.

Tool Purpose
dsniff passively collects credentials from unencrypted protocols
arpspoof forges ARP replies to redirect LAN traffic through the attacker
dnsspoof forges DNS replies
macof floods a switch with random MAC addresses to overflow its CAM table
filesnarf, mailsnarf, msgsnarf, urlsnarf, webspy extract files, mail, chat messages, URLs, and web pages from sniffed traffic
sshmitm, webmitm monkey-in-the-middle proxies for SSH and HTTPS
tcpkill, tcpnice reset or slow chosen TCP connections
sshow analyse encrypted SSH traffic patterns

Defences

  • Use encryption end to end (TLS, SSH with host key verification, VPN). Most of these tools only see plaintext or exploit users who click through certificate warnings.
  • On switches: dynamic ARP inspection, DHCP snooping, port security (MAC limits), and separate VLANs.
  • On hosts: watch for ARP anomalies (ip neigh), consider static ARP entries for critical gateways, and use tcpdump or Wireshark to check for duplicate IP/MAC announcements. See arptables.