Redirecting outgoing DNS requests toward a fake DNS server in a LAN
Maziar Janbeglou, Mazdak Zamani, Suhaimi Ibrahim · 2010
This paper shows a new DNS attack that hijacks DNS requests by frequently injecting fake DNS server, and then network systems communicate with wrong destinations. So requests with different destination DNS IP addresses can be redirected toward a fake DNS server by a hacker. This type of attack is detectable by neither the EDS nor any anti spoofing software.