<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ARP Cache Poisoning Incident</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx</link><description>I recently worked on an interesting incident response with several of my colleagues. The problem, as defined by the customer, is that the following code is being injected into some websites (both external and internal to his environment) that his users</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>ARP spoofing for fun and profit</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx#1391971</link><pubDate>Fri, 29 Jun 2007 07:15:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1391971</guid><dc:creator>Robert Hensing's Blog</dc:creator><description>&lt;p&gt;So we all know ARP poisoning / spoofing is really easy to do and it's not a new concept at all . . .&lt;/p&gt;
</description></item><item><title>http://blogs.eweek.com/cheap_hack/content/hacking/code_insertion_through_arp_cache_poisoning.html</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx#1447049</link><pubDate>Thu, 05 Jul 2007 21:51:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1447049</guid><dc:creator>TrackBack</dc:creator><description /></item><item><title>Detecting ARP Spoofing Attacks</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx#1449173</link><pubDate>Fri, 06 Jul 2007 00:20:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1449173</guid><dc:creator>Neil Carpenter's Blog</dc:creator><description>&lt;p&gt;After investigating an ARP spoofing incident recently, I started thinking of how we could easily ferret&lt;/p&gt;
</description></item><item><title>http://taosecurity.blogspot.com/2007/07/arp-spoofing-in-real-life.html</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx#1458153</link><pubDate>Fri, 06 Jul 2007 18:31:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1458153</guid><dc:creator>TrackBack</dc:creator><description /></item><item><title>ARP 缓存污染和IFRAME嵌入攻击</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx#1623238</link><pubDate>Fri, 27 Jul 2007 03:12:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1623238</guid><dc:creator>褚诚云</dc:creator><description>&lt;p&gt;ARP缓存污染（cache poison）加上IFrame 嵌入（Injection）的攻击，最近开始较多的被病毒程序使用&lt;/p&gt;
</description></item><item><title> ARP 缓存污染和IFRAME嵌入攻击</title><link>http://blogs.technet.com/neilcar/archive/2007/06/28/arp-cache-poisoning-incident.aspx#2652770</link><pubDate>Mon, 17 Dec 2007 05:40:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2652770</guid><dc:creator>csdnexpert</dc:creator><description>&lt;p&gt;最近收到了一位IT行业朋友的来信，说他遇到了这么一个现象，百思不得其解。&lt;/p&gt;
</description></item></channel></rss>