Penetration Testing mailing list archives

dns spoof windows and netbios


From: "Robin Wood" <dninja () gmail com>
Date: Mon, 25 Sep 2006 16:51:36 +0100

Hi
I'm trying to get dns spoofing working against windows XP. I'm running
dnsspoof from the dsniff package but it isn't working.

From watching packets the dns question goes across to the fake dns
server which then replies, window then does a netbios nameserver
(NBNS) lookup on the same name. As dnsspoof doesn't handle NBNS
windows doesn't get a reply so it seems to ignore the fake result
given.

I've managed to spoof windows boxes before so I don't know why this
one is different. Anyone any ideas?

In case it matters, the network is 192.168.1.x with the fake dns
server on .1 routing all dns lookups to itself. Could it be that both
addresses are on the same subnet?

Thanks

Robin

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: