DNS spoofing attack

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Grand Moff Yenchin
Sith Devotee
Posts: 2730
Joined: 2003-02-07 12:49pm
Location: Surrounded by fundies who mock other fundies
Contact:

DNS spoofing attack

Post by Grand Moff Yenchin »

My firewall has informed me that I was recieving a DNS spoofing attack, I blocked the intruder yet still was getting attacks from the same guy. Is there any firewall which could efficiently stop this?

Also, I don't quite understand the definition of DNS spoofing, what kind of damage could the attacker do?
1st Plt. Comm. of the Warwolves
Member of Justice League
"People can't see Buddha so they say he doesn't have a body, since his body is formed of atoms, of course you can't see it. Saying he doesn't have a body is correct"- Li HongZhi
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

15.3 DNS Spoofing

Clients using HTTP rely heavily on the Domain Name Service, and are thus generally prone to security attacks based on the deliberate mis-association of IP addresses and DNS names. Clients need to be cautious in assuming the continuing validity of an IP number/DNS name association.

In particular, HTTP clients SHOULD rely on their name resolver for confirmation of an IP number/DNS name association, rather than caching the result of previous host name lookups. Many platforms already can cache host name lookups locally when appropriate, and they SHOULD be configured to do so. It is proper for these lookups to be cached, however, only when the TTL (Time To Live) information reported by the name server makes it likely that the cached information will remain useful.

If HTTP clients cache the results of host name lookups in order to achieve a performance improvement, they MUST observe the TTL information reported by DNS.

If HTTP clients do not observe this rule, they could be spoofed when a previously-accessed server's IP address changes. As network renumbering is expected to become increasingly common [24], the possibility of this form of attack will grow. Observing this requirement thus reduces this potential security vulnerability.

This requirement also improves the load-balancing behavior of clients for replicated servers using the same DNS name and reduces the likelihood of a user's experiencing failure in accessing sites which use that strategy.


Source = http://www.httpsniffer.com/http/1503.htm

In short

The one attacing you could steal your traffic alter it and then pass it on, this might be bad when doing buissneses paying bills and stuff like that.

Always make sure to never send any sensetive info like Credit card numbers and stuff like that WO using secure web pages. "https://"

DNS Spoofing and man in the middle attacks:

Linkyto Power Point Slides
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Grand Moff Yenchin
Sith Devotee
Posts: 2730
Joined: 2003-02-07 12:49pm
Location: Surrounded by fundies who mock other fundies
Contact:

Post by Grand Moff Yenchin »

Thanks for the info.

After I blocked this guy there has been 3 more events, which might have been blocked successfully. If this attacker succeeds, is the false connection temporal or perminent?
1st Plt. Comm. of the Warwolves
Member of Justice League
"People can't see Buddha so they say he doesn't have a body, since his body is formed of atoms, of course you can't see it. Saying he doesn't have a body is correct"- Li HongZhi
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

A bit more info perhaps.

What os do you use?

What firewall are you using?

Do you use a router?

Do you have a dial up or some sort of permanent connection?
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Grand Moff Yenchin
Sith Devotee
Posts: 2730
Joined: 2003-02-07 12:49pm
Location: Surrounded by fundies who mock other fundies
Contact:

Post by Grand Moff Yenchin »

Faram wrote:A bit more info perhaps.

What os do you use?

What firewall are you using?

Do you use a router?

Do you have a dial up or some sort of permanent connection?
WinXP

BlackIce

No

Cable
1st Plt. Comm. of the Warwolves
Member of Justice League
"People can't see Buddha so they say he doesn't have a body, since his body is formed of atoms, of course you can't see it. Saying he doesn't have a body is correct"- Li HongZhi
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

I'd get a hardware router if I were you. Preferably one with a firewall built-in. Even if you only have one computer using broadband, its still well worth it.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Grand Moff Yenchin
Sith Devotee
Posts: 2730
Joined: 2003-02-07 12:49pm
Location: Surrounded by fundies who mock other fundies
Contact:

Post by Grand Moff Yenchin »

Thanks :)
1st Plt. Comm. of the Warwolves
Member of Justice League
"People can't see Buddha so they say he doesn't have a body, since his body is formed of atoms, of course you can't see it. Saying he doesn't have a body is correct"- Li HongZhi
User avatar
Evil Sadistic Bastard
Hentai Tentacle Demon
Posts: 4229
Joined: 2002-07-17 02:34am
Location: FREE
Contact:

Post by Evil Sadistic Bastard »

But it won't matter to you, right?
Believe in the sign of Hentai.

BotM - Hentai Tentacle Monkey/Warwolves - Evil-minded Medic/JL - Medical Jounin/Mecha Maniacs - Fuchikoma Grope Attack!/AYVB - Bloody Bastards.../GALE Force - Purveyor of Anal Justice/HAB - Combat Medical Orderly

Combat Medical Orderly(Also Nameless Test-tube Washer) : SD.Net Dept. of Biological Sciences
Post Reply