Alle leverandører

Vendor lineage

oxid.it - one man, one tool, and a site that is no longer there

Massimiliano Montoro published Cain & Abel from a personal Italian domain for over a decade; the software taught a generation how switched networks really behave, and the documentation now exists only in the Internet Archive.

oxid.it was the personal site of Italian networking consultant Massimiliano Montoro, from which he published Cain & Abel, the Windows password recovery and network analysis tool, until its last release in 2014.

It was one person's domain. Montoro, a networking consultant, published Cain & Abel from it for well over a decade, alongside advisories he wrote himself - including the 2005 disclosure of a man-in-the-middle weakness in Microsoft's remote desktop protocol, which his own tool then implemented. There was no company, no funding round and no support contract. The software was free, Windows-only, and enormously capable: sniffing, credential extraction, cryptanalysis with precomputed tables, voice call recording, wireless key recovery, and the address-resolution attack he called ARP Poison Routing.

Antivirus vendors shipped detection signatures for it, which was reasonable and also revealing - the same code was a diagnostic instrument in one pair of hands and an intrusion tool in another, and no property of the software distinguished the cases. The last release, 4.9.56, is dated 7 April 2014.

The site is gone. What made it worth an entry is not the program but the documentation: it explained the mechanisms rather than listing the buttons, and a large number of practitioners learned from it how switched networks actually behave, why a switch is not a security boundary, and what an unauthenticated protocol from 1982 permits. That material now exists only in the Internet Archive - a one-person publication that shaped professional understanding, preserved by accident rather than by anyone's intent.

Montoro's own assessment in 2009 has aged into something larger than a tool author's remark. Vendors had shipped hundreds of patches, he said, and with all of them applied his software still worked, because the protocol was unchanged - and he had never encountered a company that had considered mitigating it. Seventeen years later the protocol is still unchanged and the mitigations are still optional switch features that somebody has to decide to turn on.