Penetration Testing mailing list archives

[PEN-TEST] Arp Spoofing under WinNT 4.0


From: Fabio Pietrosanti <naif () SIKUREZZA ORG>
Date: Wed, 31 Jan 2001 12:41:47 +0100

Hi,

I'm doing a pen test, and i got access to an NT server on which i would
like to place a sniffer.

I've tried buttsniff and then Dsniff using WinPcap, but i notice that they
are on a switched network, so i  have two solutions:

1) Flood the switch of random mac address so his table will'be filled and
   the switch will operate in bride mode
2) do arp spoofing so i could intercept all packet destinated to the host
   of which traffic i need to sniff.

On unix there are many tools, but on WinNT 4.0 with WinPcap there are some
tools for "arp spoofing" ?

Thanks a lot


Best Regards

naif
naif () sikurezza org


Current thread: