Link to home
Start Free TrialLog in
Avatar of Ted
Ted

asked on

DNS spoofing

I had a partner claim that his small business was subject to a DNS attack where his staff's browsing was redirected to bogus sites.  And the attack was done from the OUTSIDE.
I think I understand how such an attack is made... you perform a man-in-the-middle where you intercept the DNS query and then return to the client an IP address to a site that you really want them to go...
But how is that really done if the attack is from the public internet?  How do you actually get the clients to send the query to you instead??  I promise I won't turn you in ;-) and I certainly am not going to do this, but how is this physically done??  Don't you have to have a registered DNS server at your control?? And don't you have to be able to hack into the client machines to change their pointers??
Is this a common occurrance?
SOLUTION
Avatar of IanTh
IanTh
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Ted
Ted

ASKER

So thru the virus or spam do they get your local machine password and then go in there to change your local resolver's parameters?

Do they get into your local DNS server and change its entries?

How are they doing it?
Avatar of Ted

ASKER

I just hit "send" and didn't see that last comment...
Reading it now... thanks
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
no they are just updating the local resource cache
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of Leon Fester
Leon Fester
Flag of South Africa image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Ted

ASKER

I did ask him and he said that his IT adjusted his firewall, he didn't get specific though.
Should I believe him?
Avatar of Ted

ASKER

Just curious if you know of an actual successful DNS attack where users were re-directed to a bogus site, and if so, how was it fixed?
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Ted

ASKER

Nope, I just have a terrible memory.

Thank you!
Avatar of Ted

ASKER

Thanks!!