当前位置:网站首页>DNS hijacking
DNS hijacking
2022-07-04 10:36:00 【I·CE】
Are simulated locally , Please do not use it in illegal ways
Xiaobai studies , If there are any errors or suggestions, please put forward
So let's see dns agreement , Of course dns It can also be used as a hidden tunnel ,,, Write it later
DNS The protocol is used to convert domain names to IP Address ( Can also be IP Convert the address to the corresponding domain name address )
dns hijacked :
Experimental environment :
Windows10( Drone aircraft ) 192.168.64.139,kali Linux( attack ) 192.168.64.133
Are all NAT Pattern , Ensure that they are in the same gateway , Be able to communicate , It can be used ping test (windows Default ping The four time ,Linux Default always ping, You can add a parameter -c To specify the ping The number of times )

Get ready :
The tools used are kali Under the ettercap, Need to be in ettercap.dns Add the following data to the file ( stay /etc/ettercap/ettercap.dns in ):
###################################################
#microsoft sucks
#redirect it to www.linux.org
microsoft.com A 107.170.40.56
*.microsoft.com A 107.170.40.56
www.microsoft.com PTR 107.170.40.56 # wildcards in PTR are not allowed
*A 192.168.64.133
*PTR 192.168.64.133
##################################################
ps: Below * Represents all parsed to the target IP
Start
open ettercap, Choose the network card eth0
hosts Choose from scan for hosts Scan host , then hosts list List the surviving hosts
Take the attack IP Add to target1, Join the gateway target2
choice ARP poisoning… that , Default ,ok, Where to find out for yourself , Different versions and positions
stay plugins choice manage plugins, choice dns_spoof
Then it began to attack
then ping Baidu will find that the analysis is kali Of ip
Little knowledge : If a website suddenly cannot be accessed, it may be that the operator hijacked your dns, Try modifying it locally hosts file
Usage expansion , Inside net fishing :
msf Create a Trojan , Let the target resolve to the server you set up , Build a website on the server , Prompt to download and upgrade the browser plug-in , Induced download generated Trojan
service apache2 start // start-up apache The server , Remember to drive 80 port
cp test.exe /var/www/html // Put the Trojan under the page
Limited ability , The page of inducing downloading and upgrading browser plug-ins cannot be written ,,, No code found , Subsequent patch ,,,
边栏推荐
- Software sharing: the best PDF document conversion tool and PDF Suite Enterprise version sharing | with sharing
- If the uniapp is less than 1000, it will be displayed according to the original number. If the number exceeds 1000, it will be converted into 10w+ 1.3k+ display
- Ruby时间格式转换strftime毫秒匹配格式
- [Galaxy Kirin V10] [server] soft RAID configuration
- /*Write a function to open the file for input, read the contents of the file into the vector container of string class 8.9: type, and store each line as an element of the container object*/
- Delayed message center design
- Rhcsa day 10 operation
- Rhcsa - day 13
- Native div has editing ability
- MongoDB数据日期显示相差8小时 原因和解决方案
猜你喜欢

VLAN part of switching technology

leetcode1-3
![[200 opencv routines] 218 Multi line italic text watermark](/img/3e/537476405f02f0ebd6496067e81af1.png)
[200 opencv routines] 218 Multi line italic text watermark

DDL statement of MySQL Foundation

【Day1】 deep-learning-basics

Some summaries of the third anniversary of joining Ping An in China

PHP code audit 3 - system reload vulnerability

Development guidance document of CMDB

From programmers to large-scale distributed architects, where are you (I)
If you don't know these four caching modes, dare you say you understand caching?
随机推荐
Rhcsa learning practice
按键精灵跑商学习-商品数量、价格提醒、判断背包
Rhsca day 11 operation
BGP ---- border gateway routing protocol ----- basic experiment
Three schemes of ZK double machine room
Remove linked list elements
Rhcsa - day 13
PHP programming language (1) - operators
BGP advanced experiment
【Day1】 deep-learning-basics
Si vous ne connaissez pas ces quatre modes de mise en cache, vous osez dire que vous connaissez la mise en cache?
RHCE day 3
Sword finger offer 31 Stack push in and pop-up sequence
[Galaxy Kirin V10] [server] grub default password
Does any teacher know how to inherit richsourcefunction custom reading Mysql to do increment?
Communication layer of csframework
Idea SSH channel configuration
Static comprehensive experiment ---hcip1
六月份阶段性大总结之Doris/Clickhouse/Hudi一网打尽
leetcode729. My schedule 1