DNS spoofing in local networks made easy

Nikhil Tripathi, Mayank Swarnkar, Neminath Hubballi · 2017

Domain Name System (DNS) is a central protocol of the internet and provides a way to resolve domain names to their corresponding IP addresses. It is one of the most critical protocols being used in the internet. However, DNS is known to be vulnerable to a popular attack called DNS poisoning. Fortunately, DNS poisoning has become difficult to launch due to introduction of techniques like source port and query identification value randomization aftermath of Kaminsky attack. In this paper, we propose a targeted DNS spoofing attack that exploits a vulnerability present in DHCP server-side IP address conflict detection technique to prevent a genuine DHCP server from offering network parameters; while sending a fake offer on its own. We discuss how proposed attack can target even a single victim client also without affecting other clients. We test the effectiveness of proposed attack in a real network setup and report the results. Further, we discuss how known detection and mitigation techniques are unable to detect the attack.

Read the paper · More papers on PaperTik