dsniff is a classic collection of network auditing and interception tools. It is included here so you can recognise what they do and defend against them. Use them only on networks you own or are explicitly authorised to test.
| Tool | Purpose |
|---|---|
dsniff |
passively collects credentials from unencrypted protocols |
arpspoof |
forges ARP replies to redirect LAN traffic through the attacker |
dnsspoof |
forges DNS replies |
macof |
floods a switch with random MAC addresses to overflow its CAM table |
filesnarf, mailsnarf, msgsnarf, urlsnarf, webspy |
extract files, mail, chat messages, URLs, and web pages from sniffed traffic |
sshmitm, webmitm |
monkey-in-the-middle proxies for SSH and HTTPS |
tcpkill, tcpnice |
reset or slow chosen TCP connections |
sshow |
analyse encrypted SSH traffic patterns |
Defences¶
- Use encryption end to end (TLS, SSH with host key verification, VPN). Most of these tools only see plaintext or exploit users who click through certificate warnings.
- On switches: dynamic ARP inspection, DHCP snooping, port security (MAC limits), and separate VLANs.
- On hosts: watch for ARP anomalies (
ip neigh), consider static ARP entries for critical gateways, and use tcpdump or Wireshark to check for duplicate IP/MAC announcements. See arptables.