Új hozzászólás Aktív témák

  • ArchElf

    addikt

    Mivel a cikkből hiányzik, Halvar Flake meglátása:


    Mallory wants to poison DNS lookups on server ns.polya.com for the domain www.gmx.net. The nameserver for gmx.net is ns.gmx.net. Mallory’s IP is 244.244.244.244.

    Mallory begins to send bogus requests for www.ulam00001.com, www.ulam00002.com … to ns.polya.com.

    ns.polya.com doesn’t have these requests cached, so it asks a root server “where can I find the .com NS?” It then receives a referral to the .com NS. It asks the nameserver for .com where to find the nameserver for ulam00001.com, ulam00002.com etc.

    Mallory spoofs referrals claiming to come from the .com nameserver to ns.polya.com. In these referrals, it says that the nameserver responsible for ulamYYYYY.com is a server called ns.gmx.net and that this server is located at 244.244.244.244. Also, the time to live of this referral is … long …

    Now eventually, Mallory will get one such referral spoofed right, e.g. the TXID etc. will be guessed properly.

    ns.polya.com will then cache that ns.gmx.net can be found at … 244.244.244.244. Yay.

    AE

    [ Szerkesztve ]

    Csinálok egy adag popcornt, és leülök fórumozni --- Ízlések és pofonok - kinek miből jutott --- Az igazi beköpőlégy [http://is.gd/cJvlC2]

Új hozzászólás Aktív témák