Unveiling DNS Spoofing Vulnerabilities: An Ethical Examination Within Local Area Networks
Asaduzzaman Jony, Muhammad Nazrul Islam, Iqbal Hasan Sarker · 2023
Nowadays DNS spoofing has become one of the terrible attacks which is triggered by exploiting IP address conflict detection vulnerability on the DHCP server side. DHCP server running on latest operating systems can detect IP address conflict which makes proposed attack ineffective. On the other hand, DNS spoofing attack using server side DNS cache poisoning is very difficult and unfeasible task as the public DNS servers are very secured and deployed behind several security appliances. Again, DNS spoofing attack is initiated by poisoning the client’s DNS cache, which is uncertain as it requires a malware to be installed in target user’s computer. Therefore, the objective of this study is to introduce an innovative approach for ethically launching a DNS spoofing attack within a Local Area Network (LAN) for illustrating the vulnerabilities and security flaws of the DNS protocol. To achieve this objective, attacker introduces a rogue DHCP server in the LAN and forcefully redirects user’s traffic to a malicious or rogue default gateway. Secondly, a python (scapy) based DNS spoofing engine is deployed in the rogue DHCP server that tampers the DNS responses replied by the DNS server. The scapy alters the IP address of legitimate website with an IP address of malicious or phishing website which is managed by the attacker and looks like legitimate website. As a result, compromised user is redirected to that identical looking phishing website and becomes victim of phishing attack. Finally, the effectiveness and validation of the proposed attack were demonstrated using the Kali Linux and multi-vendor network emulation software (EVE-NG).