Home > Networking Tips > Network Management > Network auditing with dsniff 2.3
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK MANAGEMENT

Network auditing with dsniff 2.3


Barrie Sosinsky
12.03.2003
Rating: -3.80- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


To audit network traffic you need to employ a program like a sniffer to listen to your traffic and analyze the results. If you've ever used a network monitor such as Windows' or Solaris', then you are familiar with sniffers. Commercial sniffers gather statistics and can work with various threshold and defined events. One collection of tools that has been around a few years is dsniff 2.3. This is actually a set of tools that not only audit, but test for network penetration. These programs can run on OpenBSD (x86), Red Hat Linux (x86), and Solaris (SPARC). It's been reported that users have been able to run these programs on FreeBSD, Debian Linux, Slackware Linux, AIX, and HP-UX. A version of dsniff has also been ported to Windows and MacOS X.

The dsniff ensemble includes the following tools: dsniff, filesnarf, dnsspoof, and macof, all of which intercept traffic that is protected from outsiders. Other programs such as sshmitm and webmitm in the package protect against what are referred to as "active monkey in the middle" attacks. In these sorts of attacks SSH and HTTPS traffic is redirected to another destination.

A two-part story on IBM's DeveloperWorks site is a very good introduction to the use of this tool, how it functions, and what it can and can't do. These articles are: "On the lookout for dsniff" and "On the Lookout for dsniff, part 2".


Barrie Sosinsky is president of consulting company Sosinsky and Associates (Medfield MA). He has written extensively on a variety of computer topics. His company specializes in custom software (database and Web related), training and technical documentation.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Management
Common network errors and causes
Network monitoring -- Best practices
Change management policy
Networking Products of the Year 2004
Configuring HSRP and VRRP on Cisco routers
Dust
Auto-MDIX
In search of... an affordable management platform
The best of 2004
Network administrator documentation

Network Management
Green enterprise: Three networking investments that make a difference
Distributed network management means no more hard NOCs
Green data center networks: Smarter architecture, not expensive devices
Internal cloud computing on the cheap: Free automated provisioning?
With virtual OS and virtual applications, who needs virtual machines?
Application switch testing: An easy RFP guide
Virtualization: The next generation of application delivery challenges
Improving the performance of Web traffic and application delivery
The link between network management and application delivery
How to align network usage information to business processes

Network Performance Management
Web gateway helps Texas manufacturer develop network user management
Desktop virtualization network challenges: A primer
Green enterprise: Three networking investments that make a difference
Storage area networks change management primer
CA-NetQoS deal: Network management = application performance
Virtualization change and configuration management primer
Network change and configuration management primer
Distributed network management means no more hard NOCs
WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
Network management from a service-based perspective

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
baseboard management controller  (SearchNetworking.com)
fault management  (SearchNetworking.com)
loose coupling  (SearchNetworking.com)
maximum segment size  (SearchNetworking.com)
maximum transmission unit  (SearchNetworking.com)
network coding  (SearchNetworking.com)
packet loss  (SearchNetworking.com)
phase-change cooling  (SearchNetworking.com)
round-trip time  (SearchNetworking.com)
throttled data transfer  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts