Advertisement

05.03.2008 at 01:21AM PDT, ID: 23373609
[x]
Attachment Details

How does DNS Spoofing  and SSL spoofing work with backtrack and EitherCap

Asked by rssdds in Secure Socket Layer (SSL) & HTTPS, Linux Networking, IPSec Security Protocol

Tags: IP Security

If I understand correctly the hacker must be positioned on  your immediate network or within the direct route from your workstation to the DNS server you are accessing. Isn't that right?

Isn't the scenario shown time dependent. Someone would have to automate the  process as a client may go to get a requested DNS entry
I would really appreciate it if someone could explain how this hack might be done if the hacker is not on the same lan and does not exist within the IP route between in this case the yahoo.com and some host on a NAT llan somewhere.

Here is the video.  I would sure appreciate it if someone could explain this video:
http://www.youtube.com/watch?v=Aak6-B3JORE

The very thought of DNS being subverted like that makes me sick. Very smart minds came up with SSL and it seems they were not smart enough given this video, but I suspect its limited to the hacker having access to a machine on the LAN  of the intended target?

Still someone out out there can probably explain this video better than the author of the video did
Can this technique also be used for SSH as well?

And then how do you guard against this practice?Start Free Trial
 
Loading Advertisement...
 
[+][-]05.03.2008 at 08:10AM PDT, ID: 21492581

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Secure Socket Layer (SSL) & HTTPS, Linux Networking, IPSec Security Protocol
Tags: IP Security
Sign Up Now!
Solution Provided By: marce_lito
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628