DNS Poisoning | What is it? |How to do it?

DNS(Domain name system) Poisoning also known as DNS cache poisoning.

In DNS poisoning the attacker alters the DNS records so that it can route the user to a fake website or the website which is controlled by the hacker.

This type of attack the victims will think that they are going to a real website but instead they are going to a fake website.

For e.g – They will write cybervie.com into the URL bar to visit the real website but because of DNS spoofing they will be transported to a fake website that will look like cybervie.com and they will end up giving their details to the hacker.

This creates a perfect condition for phishing attacks.

Methods of DNS spoofing/Poisoning

Man-In-The-Middle(MITM)

Hacker will intercept between the server and the user and change the user’s DNS every time the victim surf internet. Changing DNS means changing the destination IP address of the websites.

DNS poisoning Flowchart

DNS Hijacking

In DNS hijacking the the local DNS server is replaced by the forged and malicious server with IP addresses of attacker and genuine website name.

WHAT COULD GO WRONG IF YOUR DNS IS SPOOFED OR POISONED

  1. Data theft -> The attacker can compromise every type of data like your password, your credit card details, your address.
  2. Viruses/Malwares -> The attacker can download malicious software or viruses into the computer which will harm the computer badly.
  3. Stoped security updates -> If the internet security provider is spoofed it will not download the latest security updates and your device will be exposed to malware and trojans.

Tools

  1. Dnsspoof -> This tool navigates all the DNS to a fake local computer host file.
  2. Ettercap -> It is one of the best tool for man in the middle attacks(MITM) and it provides DNS spoof, arp spoof, and a lot more option for MITM
  3. Arpspoof -> This tool commands the IP address.

How to prevent DNS poisoning.

  1. Never click a link you don’t recognize.
  2. Flush you DNS cache to solve the poisoning.
  3. Use VPN.
  4. Scan your computer regularly.

 

Share the Post...
WhatsApp

About Cybervie

Cybervie provides best cyber security training program in hyderabad, India.This cyber security course enables you to detect vulnerablities of a system, wardoff attacks and manage emergency situations. Taking a proactive approach to security that can help organisations to protect their data, Cybervie has designed its training module based on the cyber security industry requirements with three levels of training in both offensive and defensive manner, and use real time scenarios which can help our students to understand the market up-to its standard certification which is an add on advantage for our students to stand out of competition in an cyber security interview.

More Info – Click Here

Recent Posts

Follow Us on Youtube

CSEP : Certified Security Engineer Professional

Certified Security Engineer Professional (CSEP) certification is a comprehensive program designed for individuals aspiring to become cybersecurity engineers. It equips candidates with hands-on knowledge across various in-demand cybersecurity domains, ensuring they are well-prepared for current and future industry needs.

Organizations today seek candidates with a diverse set of skills beyond just one tool or area of expertise. The CSEP certification addresses this need by providing essential hands-on experience, making you proficient in multiple cybersecurity domains.

The program includes live classes featuring practical exercises, followed by a real-time project that offers valuable industrial knowledge.

Domains covered in the CSEP certification:

  • Cybersecurity Essentials
  • Penetration Testing
  • Application Security
  • Security Operations
  • AI in Cybersecurity
  • Multi-Cloud Security
  • Threat Intelligence

 

This certification is ideal for those looking to secure a role as a cybersecurity engineer and want to gain a competitive edge in the cybersecurity field.

For Further kindly feel free to fill out the profile form  for relevant information on our counselor will get in touch with you

Sign up for our Newsletter

Interested in Cyber Security Training Program 2024 – Click Here
Open chat
1
Hello 👋
How can we help you?