Jump to content
begood

DNS Spoofing techniques

Recommended Posts

Posted

DNS Spoofing is the art of making a DNS entry to point to an another IP than it would

be supposed to point to. To understand better, let's see an example.

You're on your web browser and wish to see the news on www.cnn.com, without to think of

it, you just enter this URL in your address bar and press enter.

Now, what's happening behind the scenes ? Well... basically, your browser is going to

send a request to a DNS Server to get the matching IP address for www.cnn.com, then

the DNS server tells your browser the IP address of CNN, so your browser to connect

to CNN's IP address and display the content of the main page.

Hold on a minute... You get a message saying that CNN's web site has closed because

they don't have anymore money to pay for their web site. You're so amazed, you call

and tell that to your best friend on the phone, of course he's laughing at you, but

to be sure, he goes to CNN web site to check by himself.

You are surprised when he tells you he can see the news of the day as usual and you

start to wonder what's going on. Are you sure you are talking to the good IP address ?

Let's check. You ask your friend to fire up his favorite DNS resolving tool (or

simply ping) and to give you the IP address he's getting for www.cnn.com.

Once you got it, you put it in your browser URL bar : http://212.153.32.65

You feel ridiculous and frustrated when you see CNN's web page with its daily news.

Well you've just been the witness of a DNS hijacking scenario. You're wondering what

happened, did the DNS Server told you the wrong IP address ? Maybe... At least this

is the most obvious answer coming to our mind.

In fact there are two techniques for accomplishing this DNS hijacking. Let's see the

first one, the "DNS ID Spoofing" technique.

read it all here :

asdfasdfasd.jpg

http://www.securesphere.net/download/papers/dnsspoof.htm

download : http://www.2shared.com/file/12446366/fcca9422/DNS_Spoofing_techniques.html

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...