TippingPoint Digital Vaccine Laboratories

ARP spoofing for good (or evil)

Today, Pawel Pokrywka announced the release of Etherbat, a Linux application for mapping local networks. The cool part is that it does its magic through ARP spoofing.

I have a soft spot for limited information network mapping and device identification, and this does both, which makes it cool++ in my book. I've long wondered what other practical effects you could achieve with ARP spoofing (aside from the obvious route poisoning).

I've started to monkey around with Python / Impacket / Scapy to brush up on my network-fu, and once, long ago, I wrote a chat application in Perl that used fake ARP requests as the transport, called ARPArp (ARP Anonymous Relay Protocol). It's cool for interoffice chatting without any possibility of remote detection (since you're necessarily limited to the local network). Maybe this will inspire me to pick it up again. Thanks, Pawel!

Tags: netmap,software,arp,good or evil
Published On: 2007-05-31 12:08:57

Comments post a comment

No comments.
Trackback