dsniff - a great tool for your network's security
dsniff is described in it's man pages by its author as a plaintext password sniffer;
I wrote dsniff with honest intentions - to audit my own network, and to demonstrate the insecurity of cleartext network protocols. Please do not abuse this software.The purpose of this software is to be used to audit the level of security on your own network, for example, you may have a main computer, and a laptop, which accesses shared files on the main computer. You password it to keep people out, but the password is being sent in plain text across your network, for anyone to read. Dsniff just makes it easier to pinpoint the problems, so you know what to fix.
Here are some examples of protocols that use plaintext insecure passwords:
- FTP
- Telnet
- SMTP
- HTTP
- POP
- NNTP
- IMAP
- LDAP
- Rlogin
- NFS
- X11
- CVS
- IRC
- AIM
- ICQ
- PostgreSQL
- Symantec pcAnywhere
- Microsoft SMB
- Microsoft SQL protocols
- and more
Feel free to discuss the inherent problems with many of today's still commonly used plaintext protocols, and what it means for you or your business.
10 comments:
Does this have anything in common with the shiffit packet sniffer? Nice article btw, I was curious about some of the reasons why it's insecure.
- David
I think you might be referring to the sniffit program, they are both similar programs.
Thanks for article!
Thanks for interesting article.
Glad to read articles like this. Thanks to author!
Very interesting!
Very interesting article, I have long sought. It is in front of me. I agree with you!
Very interesting article, I have long sought. It is in front of me. I agree with you!
Excellent website. Good work. Very useful. I will bookmark!
Hello! Interesting article, thanks to author!
Post a Comment