logo

Analyzing ARP to Discover & Exploit Stale Network Address Configurations

ID: 980a5ff0-2f32-533a-b0cc-cac96a6cfa13

STIX ID: report--980a5ff0-2f32-533a-b0cc-cac96a6cfa13

Feed Name: Black Hills Infosec Blog

Date Published: 2019-06-12

Date Updated: 2026-04-27

Author: BHIS

...
...

This post introduces eavesarp, a Linux tool that passively and actively analyzes ARP traffic to identify Stale Network Address Configurations (SNACs), then demonstrates how adversaries can exploit SNACs via IP aliasing and packet rewriting to intercept UDP (e.g., syslog) and TCP (e.g., SMB) traffic and harvest credentials. It provides step-by-step offensive workflows, example lab scenarios, and concludes with defensive recommendations such as Dynamic ARP Inspection, monitoring anomalous ARP/DNS behavior, and tarpitting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.