Ethical Hacking and Penetration Testing Guide


What Is the Likelihood of Name Servers Allowing



Yüklə 22,44 Mb.
Pdf görüntüsü
səhifə56/235
tarix07.08.2023
ölçüsü22,44 Mb.
#138846
1   ...   52   53   54   55   56   57   58   59   ...   235
Ethical Hacking and Penetration Testing Guide ( PDFDrive )

What Is the Likelihood of Name Servers Allowing 
Recursive/Nonrecursive Queries?
A researcher queried 22,000 servers. He found that out of 22,000 systems, 13,5000 allowed non-
recursive queries and about 10,500 allowed recursive queries, which is more than 50% of the 
systems allowed recursive/nonrecursive queries.


84
◾ 
Ethical Hacking and Penetration Testing Guide
Attack Scenario
Let’s talk about some of the attack scenarios and how an attacker can benefit from dns snooping 
attack. An attacker could launch more targeted phishing attacks by figuring out what sites users are 
accessing on a network. For example, you are in the middle of the penetration test on a company’s 
network and You query their name servers to find out what sites the users are visiting. You find out 
that they are browsing “facebook.com” or “orkut.com”. Based on this, you can launch more tar-
geted phishing attacks. Also, we can launch DNS poisoning attacks to redirect all the users visiting 
Facebook to our malicious server hosted somewhere on that network. That malicious server could 
then be used to compromise the targets. We will learn more about this in Chapter 6.
Automating DNS Cache Snooping Attacks
You can build an automated script yourself or try a neat program called “FOCA,” which has the 
capability of performing DNS cache snooping attacks. We can also use an nmap script named 
“dns-cache-snoop” for automating this attack. You can learn more about these tools from follow-
ing links:
References
:

http://nmap.org/nsedoc/scripts/dns-cache-snoop.html

http://www.informatica64.com/foca.aspx
Enumerating SNMP
SNMP stands for Simple Network Mapping Protocol; it is widely used for the purpose of man-
agement and remote configurations of the devices. SNMP runs on UDP port 161. It has three 
versions: 
SNMP V1
,
 SNMP V2
,
 
and
 SNMP V3

Yüklə 22,44 Mb.

Dostları ilə paylaş:
1   ...   52   53   54   55   56   57   58   59   ...   235




Verilənlər bazası müəlliflik hüququ ilə müdafiə olunur ©azkurs.org 2024
rəhbərliyinə müraciət

gir | qeydiyyatdan keç
    Ana səhifə


yükləyin