Windows

DNS SPOOFING- Tricking a DNS server into installing a false IP address

10 Comments 27 January 2010

spoofer 300x205 DNS SPOOFING  Tricking a DNS server into installing a false IP address

DNS SPOOFING- Tricking a DNS server into installing a false IP address is called DNS spoofing. For example, suppose Trudy is able to crack the DNS system, may be just the DNS cache at Alice’s ISP, and replace Bob’s IP address with her (Trudy’s) IP address. When Alice looks up Bob’s IP address, she gets Trudy’s, so all her traffic intended for Bob goes to Trudy. Trudy can now mount a man-in-the-middle attack without having to go to the trouble of tapping any phone lines. Instead she has to break into a DNS server and change one record, a much easier proposition.

How might Trudy fool DNS? It turns out to be relatively easy. Trudy can trick the DNS server at Alice’s ISP into sending out a query to look up Bob’s address .Unfortunately since DNS uses UDP; the DNS server has no real way of checking who supplied the answer. Trudy can exploit this property by forging the expected reply and thus injecting a false IP address into the DNS server’s cache.

Trudy starts the attack by sending a lookup request to Alice’s ISP asking for the IP address of Bob’s. Since there is one entry for this DNS name, the cache server queries the top level server for the com domain to get one. However Trudy beats the com server to the punch and sends back a false reply. If her false reply gets back to Alice’s ISP first, that one will be cached and the real reply will be rejected as an unsolicited reply to a query no longer outstanding. A cache that holds an intentionally false IP address like this is called a poisoned cache.

Share and Enjoy:
  • Print
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • BlinkList
  • blogmarks
  • Blogosphere News
  • email
  • FriendFeed
  • LinkedIn
  • Live
  • MySpace
  • Netvibes
  • Ping.fm
  • Posterous
  • Propeller
  • Reddit
  • SphereIt
  • StumbleUpon
  • Technorati
  • Tumblr
  • Yahoo! Buzz
  • Add to favorites
  • blogtercimlap
  • Diggita
  • Diigo
  • DZone
  • Fark
  • Faves
  • Gwar
  • IndianPad
  • LinkArena
  • muti
  • N4G
  • Netvouz
  • NewsVine
  • PDF
  • Rec6
  • Scoopeo
  • Segnalo
  • SheToldMe
  • Simpy
  • Slashdot
  • Socialogs
  • ThisNext
  • Tipd
  • Twitter
  • Upnews
  • viadeo FR
  • Webnews.de
  • Webride
  • Wikio
  • Yahoo! Bookmarks
  • Yigg
  • BarraPunto
  • Bitacoras.com
  • connotea
  • Current
  • Design Float
  • DotNetKicks
  • eKudos
  • Fleck
  • FSDaily
  • Global Grind
  • HelloTxt
  • Hyves
  • Internetmedia
  • Kirtsy
  • Linkter
  • Meneame
  • MisterWong
  • MOB
  • MSN Reporter
  • MyShare
  • NuJIJ
  • Ratimarks
  • RSS
  • Xerpi

Related Posts

Your Comments

10 Comments so far

  1. nitin says:

    nice post for dns spoofing.

  2. nitinsingh says:

    nice post for DNS spoofing.

  3. VISHAL says:

    Useful Article..Thanks for share

  4. Simran says:

    That’s a nice trick.. Can you guest post on my blog with some tricky posts ?

  5. Loveish says:

    Nice trick..thnx for sharing

  6. VISHAL says:

    Well well well…Juz came to know more about Domain Name System.. Nice share

  7. I always thought IP address tracking was accurate and spoof-proof. Thanks for sharing

  8. VISHAL says:

    Even i was thinkin d same ellen

  9. Nolan says:

    I think the bad-virus-creating hackers are using this method already — that’s why they can’t be tracked and shut down. What a shame! I hope something like this can actually be put to GOOD use for a change.


Share your view

Post a comment

CommentLuv Enabled

Subscribe

Enter your email address:

Delivered by FeedBurner

sizlopedia on Facebook
Loading
Increase your website traffic with Attracta.com

© 2010 Sizlopedia. Powered by Wordpress.