ARP Spoofing is a technique that every security consultant will scare their clients with as a means to prove the point that nothing within the network is safe from eavesdropping. So what is it? ARP spoofing, also known as ARP poisoning, is a technique used to attack an Ethernet network. It allows an attacker to sniff data frames on a local area network (LAN), modify the traffic, or stop the traffic altogether. Something that should be mentioned here from the outset; this is nothing new, ARP Spoofing is well known and understood in the security community, such an understanding has resulted in technologies being developed to combat the attack.
What is new, however, is that malware authors have seen the potential of this attack and are starting to use it. What is it? Firstly what is ARP, it is the Address Resolution Protocol (ARP), it is a standard way to locate a device’s hardware address when only the network address is known. It is not an IP only or Ethernet only protocol, it can be used in many other environments, however due to the prevalence of IP and Ethernet environments it is primarily used to translate IP Addresses to Ethernet MAC Addresses. You can find a more detailed description of the entire protocol here. Virus.Org - ARP Spoofing Malware
From around the Web
- Windows Vista Service Pack 2 Latest Release Schedule
- Vista SP2: What is inside?
- NetWitness releases free version of security software
- Three Reasons Why Users Won’t Buy Into Security
- Automated security testing & its limitations
- Google Wants to Preinstall Chrome Browser on PCs
- Mozilla warns of Firefox China add on
- Firefox No Longer an Automatic Defense Against Browser Drive Bys
- Google patches Chrome file stealing bug
- Apple plays catch up, adds anti fraud safeguard to Safari
- Researchers find vulnerability in Windows Vista
- How to Use Network Behavior Analysis Tools
- The insider security threat in IT and financial services
- Windows 7 security: An overall improvement?
- Windows 7 UAC could be less of a nag