Analyzing ARP to Discover & Exploit Stale Network Address Configurations
ID: 980a5ff0-2f32-533a-b0cc-cac96a6cfa13
STIX ID: report--980a5ff0-2f32-533a-b0cc-cac96a6cfa13
Feed Name: Black Hills Infosec Blog
This post introduces eavesarp, a Linux tool that passively and actively analyzes ARP traffic to identify Stale Network Address Configurations (SNACs), then demonstrates how adversaries can exploit SNACs via IP aliasing and packet rewriting to intercept UDP (e.g., syslog) and TCP (e.g., SMB) traffic and harvest credentials. It provides step-by-step offensive workflows, example lab scenarios, and concludes with defensive recommendations such as Dynamic ARP Inspection, monitoring anomalous ARP/DNS behavior, and tarpitting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
