From: lists Date: 2009-03-17T22:50:27+09:00 Subject: Re: detect rogue DHCP server On Mar 17, 2009, at 7:16 AM, Eleanor McHugh wrote: > In the presentation we also cover the use of libpcap for watching on- > the-wire traffic and that's probably the way to go for detecting the > ACK packet if you have the privileges to put your NIC in promiscuous > mode. > > You'll also find a slew of network code of varying quality scattered > through the other linked presentations and some of that may give you > inspiration: the UDP client examples in the "Semantic DNS" and > "Shoes" presentations are particularly lightweight and should (with > a big "I'm guessing without writing the code myself" disclaimer) > apply equally to raw sockets. Ellie, you generously reference your slides pretty frequently. Had you ever given thought to fleshing out some of your ideas in a book or downloadable pdf?