• Home
  • History
  • Annotate
Name Date Size #Lines LOC

..03-May-2022-

missing/H07-May-2022-1,493806

CHANGESH A D19-Mar-20016.3 KiB258130

LICENSEH A D14-Nov-20001.4 KiB2822

Makefile.inH A D03-May-20224.8 KiB165111

READMEH A D17-Mar-20013.9 KiB11490

TODOH A D02-Dec-2000387 168

acconfig.hH A D28-Nov-2000541 2310

arp.cH A D03-May-20222.3 KiB12293

arp.hH A D15-Mar-2001273 174

arpspoof.8H A D28-Nov-2000899 3837

arpspoof.cH A D03-May-20224.2 KiB212161

asn1.cH A D15-Mar-2001823 6847

asn1.hH A D15-Mar-2001328 238

base64.cH A D15-Mar-20018.4 KiB24696

base64.hH A D15-Mar-2001212 164

buf.cH A D03-May-20223.8 KiB266203

buf.hH A D15-Mar-20011.8 KiB8332

config.h.inH A D28-Nov-20002.7 KiB11175

configureH A D19-Mar-2001104.6 KiB3,5993,016

configure.inH A D20-Dec-20008.9 KiB341325

decode.cH A D15-Mar-20015.1 KiB203167

decode.hH A D15-Mar-20013.4 KiB8762

decode_aim.cH A D03-May-20222.2 KiB11978

decode_citrix.cH A D15-Mar-20011.3 KiB7440

decode_cvs.cH A D15-Mar-20012.1 KiB7651

decode_ftp.cH A D15-Mar-20011.1 KiB6136

decode_hex.cH A D15-Mar-20011.2 KiB6541

decode_http.cH A D15-Mar-20014.1 KiB200157

decode_icq.cH A D15-Mar-20014.2 KiB162116

decode_imap.cH A D15-Mar-2001834 4727

decode_irc.cH A D15-Mar-20011.6 KiB7757

decode_ldap.cH A D15-Mar-20011.7 KiB9155

decode_mmxp.cH A D15-Mar-20011.9 KiB9654

decode_mountd.cH A D15-Mar-20011.8 KiB8461

decode_napster.cH A D15-Mar-2001831 5126

decode_nntp.cH A D15-Mar-20011.2 KiB6242

decode_oracle.cH A D15-Mar-20011.4 KiB7245

decode_ospf.cH A D15-Mar-2001494 3415

decode_pcanywhere.cH A D15-Mar-20011.6 KiB8250

decode_pop.cH A D15-Mar-20011.6 KiB7853

decode_portmap.cH A D15-Mar-20011.6 KiB7154

decode_postgresql.cH A D15-Mar-20011 KiB6339

decode_pptp.cH A D03-May-20224.8 KiB215166

decode_rip.cH A D15-Mar-2001583 3515

decode_rlogin.cH A D15-Mar-20011 KiB5430

decode_smb.cH A D15-Mar-20011.7 KiB9164

decode_smtp.cH A D15-Mar-20011.1 KiB5639

decode_sniffer.cH A D15-Mar-2001981 5230

decode_snmp.cH A D15-Mar-20011 KiB5634

decode_socks.cH A D15-Mar-2001999 6134

decode_tds.cH A D03-May-20224 KiB208149

decode_telnet.cH A D15-Mar-2001573 3818

decode_vrrp.cH A D03-May-20221.5 KiB7140

decode_x11.cH A D15-Mar-2001667 4422

decode_yp.cH A D15-Mar-20013.2 KiB146114

dnsspoof.8H A D14-Nov-20001.1 KiB4241

dnsspoof.cH A D03-May-20226.6 KiB334252

dnsspoof.hostsH A D19-Nov-20001.1 KiB4948

dsniff.8H A D15-Dec-20002.6 KiB8281

dsniff.cH A D15-Mar-20013.1 KiB182144

dsniff.magicH A D14-Nov-20001.8 KiB11186

dsniff.servicesH A D15-Dec-20001.1 KiB7170

filesnarf.8H A D19-Nov-2000699 3433

filesnarf.cH A D03-May-202210.1 KiB513412

hex.cH A D15-Mar-20011.5 KiB8055

hex.hH A D15-Mar-2001344 205

install-shH A D14-Nov-20004.7 KiB239152

macof.8H A D14-Nov-20001 KiB4544

macof.cH A D03-May-20223.3 KiB157116

magic.cH A D15-Mar-200117.5 KiB848664

magic.hH A D15-Mar-2001339 195

mailsnarf.8H A D19-Nov-2000836 3534

mailsnarf.cH A D15-Mar-20017.5 KiB392311

mount.xH A D09-Dec-20005.9 KiB18957

msgsnarf.8H A D19-Nov-2000726 3534

msgsnarf.cH A D15-Mar-200114.5 KiB680560

nfs_prot.xH A D14-Nov-20007.3 KiB397275

options.hH A D15-Mar-2001401 2511

pathnames.hH A D15-Mar-2001383 228

pcaputil.cH A D03-May-20221.8 KiB11187

pcaputil.hH A D15-Mar-2001352 216

record.cH A D03-May-20223.9 KiB219164

record.hH A D15-Mar-2001424 258

remote.cH A D14-Nov-200018.2 KiB696580

rpc.cH A D15-Mar-20012.3 KiB13491

rpc.hH A D15-Mar-2001595 3416

ssh.cH A D15-Mar-200114 KiB582456

ssh.hH A D15-Mar-20011.4 KiB7444

sshcrypto.cH A D03-May-20224.2 KiB197139

sshcrypto.hH A D15-Mar-2001869 2911

sshmitm.8H A D15-Dec-2000825 3736

sshmitm.cH A D03-May-20228 KiB408314

sshow.8H A D17-Mar-2001860 4039

sshow.cH A D19-Mar-200116 KiB664551

tcp_raw.cH A D03-May-20224.8 KiB237184

tcp_raw.hH A D03-May-2022566 249

tcpkill.8H A D17-Mar-2001802 3534

tcpkill.cH A D03-May-20223.1 KiB152108

tcpnice.8H A D17-Mar-2001806 3938

tcpnice.cH A D03-May-20224.9 KiB226167

trigger.cH A D03-May-202212.9 KiB589479

trigger.hH A D03-May-2022879 3618

urlsnarf.8H A D19-Nov-2000904 3837

urlsnarf.cH A D03-May-20224.9 KiB250197

version.hH A D19-Mar-200123 21

vroot.hH A D14-Nov-20004.8 KiB12050

webmitm.8H A D17-Mar-2001722 3534

webmitm.cH A D03-May-202210.1 KiB533418

webspy.8H A D14-Nov-2000631 3130

webspy.cH A D03-May-20224.6 KiB227168

README

1
2dsniff-2.3
3----------
4
5i wrote these tools with honest intentions - to audit my own network,
6and to demonstrate the insecurity of cleartext / weakly-encrypted
7network protocols and ad-hoc PKI. please do not abuse this software.
8
9these programs require:
10
11      Berkeley DB - http://www.sleepycat.com/
12      OpenSSL - http://www.openssl.org/
13      libpcap - http://www.tcpdump.org/
14      libnids - http://www.packetfactory.net/Projects/Libnids/
15      libnet - http://www.packetfactory.net/Projects/Libnet/
16
17built and tested on OpenBSD, Linux, and Solaris. YMMV.
18
19what's here:
20
21arpspoof
22	redirect packets from a target host (or all hosts) on the LAN
23	intended for another local host by forging ARP replies. this
24	is an extremely effective way of sniffing traffic on a switch.
25	kernel IP forwarding (or a userland program which accomplishes
26	the same, e.g. fragrouter :-) must be turned on ahead of time.
27
28dnsspoof
29	forge replies to arbitrary DNS address / pointer queries on
30	the LAN. this is useful in bypassing hostname-based access
31	controls, or in implementing a variety of man-in-the-middle
32	attacks (HTTP, HTTPS, SSH, Kerberos, etc).
33
34dsniff
35	password sniffer. handles FTP, Telnet, SMTP, HTTP, POP,
36	poppass, NNTP, IMAP, SNMP, LDAP, Rlogin, RIP, OSPF, PPTP
37	MS-CHAP, NFS, VRRP, YP/NIS, SOCKS, X11, CVS, IRC, AIM, ICQ,
38	Napster, PostgreSQL, Meeting Maker, Citrix ICA, Symantec
39	pcAnywhere, NAI Sniffer, Microsoft SMB, Oracle SQL*Net, Sybase
40	and Microsoft SQL auth info.
41
42	dsniff automatically detects and minimally parses each
43	application protocol, only saving the interesting bits, and
44	uses Berkeley DB as its output file format, only logging
45	unique authentication attempts. full TCP/IP reassembly is
46	provided by libnids(3) (likewise for the following tools as
47	well).
48
49filesnarf
50	saves selected files sniffed from NFS traffic in the current
51	working directory.
52
53macof
54	flood the local network with random MAC addresses (causing
55	some switches to fail open in repeating mode, facilitating
56	sniffing). a straight C port of the original Perl Net::RawIP
57	macof program.
58
59mailsnarf
60	a fast and easy way to violate the Electronic Communications
61	Privacy Act of 1986 (18 USC 2701-2711), be careful. outputs
62	selected messages sniffed from SMTP and POP traffic in Berkeley
63	mbox format, suitable for offline browsing with your favorite
64	mail reader (mail -f, pine, etc.).
65
66msgsnarf
67	record selected messages from sniffed AOL Instant Messenger,
68	ICQ 2000, IRC, and Yahoo! Messenger chat sessions.
69
70sshmitm
71	SSH monkey-in-the-middle. proxies and sniffs SSH traffic
72	redirected by dnsspoof(8), capturing SSH password logins, and
73	optionally hijacking interactive sessions. only SSH protocol
74	version 1 is (or ever will be) supported - this program is far
75	too evil already.
76
77sshow
78	SSH traffic analysis tool. analyzes encrypted SSH-1 and SSH-2
79	traffic, identifying authentication attempts, the lengths of
80	passwords entered in interactive sessions, and command line
81	lengths.
82
83tcpkill
84	kills specified in-progress TCP connections (useful for
85	libnids-based applications which require a full TCP 3-whs for
86	TCB creation).
87
88tcpnice
89	slow down specified TCP connections via "active" traffic
90	shaping. forges tiny TCP window advertisements, and optionally
91	ICMP source quench replies.
92
93urlsnarf
94	output selected URLs sniffed from HTTP traffic in CLF
95	(Common Log Format, used by almost all web servers), suitable
96	for offline post-processing with your favorite web log
97	analysis tool (analog, wwwstat, etc.).
98
99webmitm
100	HTTP / HTTPS monkey-in-the-middle. transparently proxies and
101	sniffs web traffic redirected by dnsspoof(8), capturing most
102	"secure" SSL-encrypted webmail logins and form submissions.
103
104webspy
105	sends URLs sniffed from a client to your local Netscape
106	browser for display, updated in real-time (as the target
107	surfs, your browser surfs along with them, automagically).
108	a fun party trick. :-)
109
110-d.
111
112---
113http://www.monkey.org/~dugsong/
114