当前位置:网站首页>DNS hijacking
DNS hijacking
2022-07-04 10:36:00 【I·CE】
Are simulated locally , Please do not use it in illegal ways
Xiaobai studies , If there are any errors or suggestions, please put forward
So let's see dns agreement , Of course dns It can also be used as a hidden tunnel ,,, Write it later
DNS The protocol is used to convert domain names to IP Address ( Can also be IP Convert the address to the corresponding domain name address )
dns hijacked :
Experimental environment :
Windows10( Drone aircraft ) 192.168.64.139,kali Linux( attack ) 192.168.64.133
Are all NAT Pattern , Ensure that they are in the same gateway , Be able to communicate , It can be used ping test (windows Default ping The four time ,Linux Default always ping, You can add a parameter -c To specify the ping The number of times )
Get ready :
The tools used are kali Under the ettercap, Need to be in ettercap.dns Add the following data to the file ( stay /etc/ettercap/ettercap.dns in ):
###################################################
#microsoft sucks
#redirect it to www.linux.org
microsoft.com A 107.170.40.56
*.microsoft.com A 107.170.40.56
www.microsoft.com PTR 107.170.40.56 # wildcards in PTR are not allowed
*A 192.168.64.133
*PTR 192.168.64.133
##################################################
ps: Below * Represents all parsed to the target IP
Start
open ettercap, Choose the network card eth0
hosts Choose from scan for hosts Scan host , then hosts list List the surviving hosts
Take the attack IP Add to target1, Join the gateway target2
choice ARP poisoning… that , Default ,ok, Where to find out for yourself , Different versions and positions
stay plugins choice manage plugins, choice dns_spoof
Then it began to attack
then ping Baidu will find that the analysis is kali Of ip
Little knowledge : If a website suddenly cannot be accessed, it may be that the operator hijacked your dns, Try modifying it locally hosts file
Usage expansion , Inside net fishing :
msf Create a Trojan , Let the target resolve to the server you set up , Build a website on the server , Prompt to download and upgrade the browser plug-in , Induced download generated Trojan
service apache2 start // start-up apache The server , Remember to drive 80 port
cp test.exe /var/www/html // Put the Trojan under the page
Limited ability , The page of inducing downloading and upgrading browser plug-ins cannot be written ,,, No code found , Subsequent patch ,,,
边栏推荐
- Network connection (III) functions and similarities and differences of hubs, switches and routers, routing tables and tables in switches, why do you need address translation and packet filtering?
- Es advanced series - 1 JVM memory allocation
- If you don't know these four caching modes, dare you say you understand caching?
- When I forget how to write SQL, I
- How to quickly parse XML documents through C (in fact, other languages also have corresponding interfaces or libraries to call)
- System. Currenttimemillis() and system Nanotime (), which is faster? Don't use it wrong!
- 如果不知道這4種緩存模式,敢說懂緩存嗎?
- On binary tree (C language)
- IPv6 comprehensive experiment
- DDL language of MySQL database: create, modify alter, delete drop of databases and tables
猜你喜欢
【FAQ】华为帐号服务报错 907135701的常见原因总结和解决方法
[Galaxy Kirin V10] [server] NUMA Technology
Introduction to extensible system architecture
Two way process republication + routing policy
MFC document view framework (relationship between classes)
[Galaxy Kirin V10] [desktop] cannot add printer
Safety reinforcement learning based on linear function approximation safe RL with linear function approximation translation 2
Error C4996 ‘WSAAsyncSelect‘: Use WSAEventSelect() instead or define _ WINSOCK_ DEPRECATED_ NO_ WARN
Network connection (II) three handshakes, four waves, socket essence, packaging of network packets, TCP header, IP header, ACK confirmation, sliding window, results of network packets, working mode of
Static comprehensive experiment ---hcip1
随机推荐
DDL language of MySQL database: create, modify alter, delete drop of databases and tables
Time complexity and space complexity
[Galaxy Kirin V10] [desktop] cannot add printer
Rhcsa12
20 minutes to learn what XML is_ XML learning notes_ What is an XML file_ Basic grammatical rules_ How to parse
基于线性函数近似的安全强化学习 Safe RL with Linear Function Approximation 翻译 1
按键精灵跑商学习-商品数量、价格提醒、判断背包
Three schemes of ZK double machine room
When I forget how to write SQL, I
Use the data to tell you where is the most difficult province for the college entrance examination!
Write a program to judge whether the two arrays are equal, and then write a similar program to compare the two vectors.
From programmers to large-scale distributed architects, where are you (2)
Add t more space to your computer (no need to add hard disk)
uniapp 处理过去时间对比现在时间的时间差 如刚刚、几分钟前,几小时前,几个月前
[Galaxy Kirin V10] [server] grub default password
How do microservices aggregate API documents? This wave of show~
Rhcsa learning practice
[Galaxy Kirin V10] [desktop] login system flash back
Whether a person is reliable or not, closed loop is very important
How to use diff and patch to update the source code