Return-Path: <security-internal-request@MIT.EDU>
Received: from grand-central-station.MIT.EDU by po12.mit.edu (8.9.2/4.7) id TAA13076; Thu, 7 Dec 2000 19:07:52 -0500 (EST)
Received: from melbourne-city-street.MIT.EDU (MELBOURNE-CITY-STREET.MIT.EDU [18.69.0.45]) by grand-central-station.MIT.EDU (8.9.2/8.9.2) with ESMTP id TAA19420 for <security-internal@MIT.EDU>; Thu, 7 Dec 2000 19:07:50 -0500 (EST)
Received: from tiramisu.lcs.mit.edu (tiramisu.lcs.mit.edu [18.26.4.96]) by melbourne-city-street.MIT.EDU (8.9.3/8.9.2) with ESMTP id TAA28030 for <security-internal@MIT.EDU>; Thu, 7 Dec 2000 19:07:50 -0500 (EST)
Received: by tiramisu.lcs.mit.edu (8.8.7/4.7) id TAA12944; Thu, 7 Dec 2000 19:08:01 -0500
Message-Id: <200012080008.TAA12944@tiramisu.lcs.mit.edu>
To: security-internal@MIT.EDU
Subject: Dug Song: dsniff sneak peek
Date: Thu, 07 Dec 2000 19:08:01 EST
From: Kevin Fu <fubob@MIT.EDU>
Status: O
X-Status: 
X-Keywords:                  
X-UID: 13
X-Evolution: 0000000c-0000

------- Forwarded Message
Date: Thu, 7 Dec 2000 18:57:19 -0500
From: Dug Song <dugsong@monkey.org>
To: monkeys@monkey.org
Subject: dsniff sneak peek

just wanted to invite you to take a sneak peek at the next version of
dsniff, to be released on its first birthday, Dec. 17th. :-)

version 2.3 includes new tools dnsspoof, sshmitm, webmitm, and
msgsnarf. in conjunction with dnsspoof, sshmitm allows you to
intercept SSH connections for interactive monitoring and hijacking.
webmitm allows you to sniff sensitive data out of SSL-encrypted web
requests / form submissions, a neat trick i demonstrated to Niels by
showing him his online banking login/password. :-)

to my knowledge, this is the first public implementation of a
man-in-the-middle toolkit to defeat PKI-based encrypted
protocols. i'll probably go after Lucent's proprietary (D-H)
PubStation auth next, unless they go to PPP over 802.11...

	http://www.monkey.org/~dugsong/dsniff/beta/dsniff-2.3b5.tar.gz

i'll have a FAQ available for this release as well:

	http://www.monkey.org/~dugsong/dsniff/faq.html

anyhow, just wanted to give a heads-up, so you know what's going on if
you see your SSH host keys change. ;-)

- -d.

- ---
http://www.monkey.org/~dugsong/

------- End of Forwarded Message


