nerdexam
GIAC

GCIH · Question #309

Which of the following statements are true about Dsniff? Each correct answer represents a complete solution. Choose two.

The correct answer is A. It contains Trojans. D. It is a collection of various hacking tools. Dsniff is a well-known open-source network auditing and penetration testing toolkit originally written by Dug Song. It is a collection of various hacking/network attack tools - this includes utilities like dsniff (a password sniffer), arpspoof (for ARP poisoning/MITM attacks)…

Web Application Attacks & Post-Exploitation

Question

Which of the following statements are true about Dsniff? Each correct answer represents a complete solution. Choose two.

Options

  • AIt contains Trojans.
  • BIt is a virus.
  • CIt is antivirus.
  • DIt is a collection of various hacking tools.

How the community answered

(23 responses)
  • A
    87% (20)
  • B
    4% (1)
  • C
    9% (2)

Explanation

Dsniff is a well-known open-source network auditing and penetration testing toolkit originally written by Dug Song. It is a collection of various hacking/network attack tools - this includes utilities like dsniff (a password sniffer), arpspoof (for ARP poisoning/MITM attacks), urlsnarf, mailsnarf, webspy, sshmitm, webmitm, and others. Because it bundles offensive capabilities together in one package, many antivirus and security products flag components within it as Trojans or malicious software - hence the statement that 'it contains Trojans' is considered correct in this context (its tools can behave like Trojans by intercepting credentials and communications). It is neither a virus (self-replicating malicious code) nor an antivirus product - both of those options are clearly false.

Topics

#DSniff#network sniffing tools#credential harvesting#hacking toolkit

Community Discussion

No community discussion yet for this question.

Full GCIH Practice