All language subtitles for 10. DNS Spoofing - Controlling DNS Requests on The Network

af Afrikaans
ak Akan
sq Albanian
am Amharic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1 1

Now in this lecture, 2

2

we're going to learn what DNS spoofing is 3

3

and how to perform it. 4

4

DNS is a server that converts domain names, 5

5

such as google.com, to the IP of the server 6

6

that is hosting this website. 7

7

So, when you type google.com in your web browser, 8

8

the request goes to a DNS server, 9

9

the server responds with the IP 10

10

where google.com files are stored, 11

11

and the browser will load the website 12

12

from this IP. 13

13

Now, when we are the man in the middle, 14

14

the request for google.com 15

15

will pass through us first 16

16

before it goes to the DNS server. 17

17

Therefore, instead of giving the IP 18

18

of the server that is hosting google.com, 19

19

we can actually give any IP we want. 20

20

So we can redirect them to a fake website 21

21

with a backdoor or with evil code, 22

22

hijack software updates and so much more. 23

23

We'll actually have examples on this 24

24

in future lectures but for now 25

25

let's see how we can run 26

26

a basic DNS spoofing attack, 27

27

in which we redirect requests 28

28

from a specific website to our own website 29

29

or our own web server. 30

30

Now before we run bettercap, 31

31

let's decide on where to redirect our target to. 32

32

So, we can redirect them to any website we want, 33

33

for example when someone requests google.com, 34

34

we can redirect them to Yahoo. 35

35

But what I want to do is 36

36

I want to redirect them to my own website, 37

37

to a local website that I'm gonna start on Kali. 38

38

Kali comes with its own web server 39

39

so we can actually use it as a website 40

40

and to do this, all we have to do 41

41

is just start the web server 42

42

so we're gonna do service apache2 start. 43

43

So apache2 is the name of the web server 44

44

and we're saying that we want to start this service. 45

45

If I hit Enter, we see no errors, 46

46

which means that the server is working now. 47

47

And to access this website, 48

48

to access this server, 49

49

we have to go to Kali's IP. 50

50

So as you know, to get our IP we can do ifconfig, 51

51

and we can see our IP is 10.0.2.15. 52

52

So if I just go to a web browser 53

53

and go to 10.0.2.15, 54

54

you'll see I'll get the default page of this website. 55

55

Now, the pages for this default web site 56

56

is stored in var/www/html. 57

57

So I'm gonna open my file manager 58

58

and I'm gonna click here on the title bar, 59

59

press forward slash to open it, 60

60

and we're gonna go to var/www/html, 61

61

and as you can see, these are the files 62

62

for this website. 63

63

So if you want to install a fake website 64

64

or any type of website, all you have to do 65

65

is just put its files in here. 66

66

Now, index.html is the file 67

67

that gets loaded here by default. 68

68

So this is what you see in here. 69

69

So I'm actually gonna right-click it. 70

70

I'm gonna open it with another application. 71

71

I'm gonna select my Text Editor. 72

72

This will open the html code for me, 73

73

and I'm actually just gonna remove this, 74

74

and I'll just put a smiley face. 75

75

Like I said, we're just doing this for testing, 76

76

so just showing you which files get loaded by default 77

77

and where you can actually put a website 78

78

if you wanted to host a proper website here. 79

79

So, I'm gonna go back here and if I refresh the page, 80

80

you can see we get the smiley face in here. 81

81

Now that's perfect. 82

82

Right now we still haven't executed 83

83

our DNS spoofing attack 84

84

but what I want to do is, 85

85

when my target tries to go to a specific website 86

86

I'm gonna redirect them to this page 87

87

that shows the smiley face. 88

88

So let's go to the target machine first 89

89

and let's go to our target website. 90

90

I'm gonna do this against my own website, 91

91

zsecurity.org. 92

92

So if you load this website, 93

93

you'll see we'll get an actual security website 94

94

with a number of topics and all that kind of stuff. 95

95

Basically the website is working as expected. 96

96

Now let's go ahead and run this attack. 97

97

So I'm gonna go to bettercap. 98

98

I'm gonna run it using the exact same command 99

99

that we've been using so far. 100

100

So we're just doing bettercap 101

101

with the interface with the spoof caplet 102

102

so we can intercept data and modify it 103

103

as it's flowing through our computer. 104

104

And as you can see, it's running with no errors 105

105

so that's all good. 106

106

Now, the module that we want to use 107

107

is called dns spoof. 108

108

So if I do help right now, 109

109

you can see it right here, 110

110

it's called dns spoof and it's not running. 111

111

And as usual, if we don't know how to use a module, 112

112

all we have to do is do help 113

113

followed by the module name 114

114

and in this case it's dns spoof. 115

115

And as you can see we get all the options 116

116

that we can set for this module. 117

117

First option being the dns spoof address. 118

118

This is the address that the user 119

119

will be redirected to. 120

120

So if you want to redirect them 121

121

to another website, you have to put 122

122

the IP of this other website here. 123

123

In my case I want to redirect them 124

124

to my local website, 125

125

to the website that we have here, 126

126

which is running at 10.0.2.15. 127

127

Therefore, I'm not gonna have to modify this 128

128

because by default this is set 129

129

to the IP of my interface. 130

130

The next thing that we want to modify 131

131

is the dns.spoof.all. 132

132

We want to set this to true 133

133

so that bettercap responds 134

134

to any DNS request. 135

135

So just like any other option within bettercap 136

136

to change its value, we have to do set, 137

137

followed by the option name 138

138

that we want to modify, 139

139

and in this case it's dns.spoof.all, 140

140

and we want to set this to true. 141

141

Sorry, this is all being produced by the sniffer. 142

142

The next option that we want to set 143

143

is the dns.spoof.domains. 144

144

This will specify the domains 145

145

that we want to target, 146

146

that we want to spoof. 147

147

And as mentioned, we can use a comma 148

148

to separate more than one domain. 149

149

And as you know, we want to target zsecurity.org 150

150

and we want to redirect that 151

151

to our own website running on Kali. 152

152

So, we need to change this option right here, 153

153

dns.spoof.domains, and again, 154

154

we're gonna do this by doing set, 155

155

the option name, which is dns.spoof.domains, 156

156

and we're gonna set this to zsecurity.org. 157

157

As mentioned in the option 158

158

we can use the comma 159

159

to specify more than one domain 160

160

and the other domain that I want to specify 161

161

is star .zsecurity.org. 162

162

So the star right here is a wildcard 163

163

and it basically means that I want to target 164

164

any subdomain .zsecurity.org. 165

165

So I'm gonna hit Enter 166

166

and we don't see any errors 167

167

so everything is set as expected. 168

168

And all we need to do now 169

169

is start the dns spoof and to do this, 170

170

we just need to run dns.spoof 171

171

on exactly the same way that we start 172

172

any other module. 173

173

I'm gonna hit Enter and this should be running right now 174

174

and as you can see, it's telling us 175

175

that it's going to spoof zsecurity.org 176

176

to this IP, which is again, this is our IP, 177

177

we verified this using the ifconfig command. 178

178

And keep in mind, we actually did not have 179

179

to give bettercap this IP. 180

180

It got it automatically. 181

181

It's also telling us that the other target 182

182

is star .zsecurity.org 183

183

and it'll be spoofed to this. 184

184

Now, let's go to the target machine 185

185

and test this and before you test this, 186

186

please keep in mind you might need to wait 187

187

for a minute or two for the changes to propagate. 188

188

Also, if you just loaded this website, 189

189

just like I did right now, 190

190

it's a good idea to remove all your browsing data. 191

191

You won't have to do this in real-life scenarios 192

192

unless the target person is constantly loading 193

193

the same page, which doesn't happen a lot. 194

194

But if the target person goes ahead 195

195

and browses a few websites, 196

196

comes back to zsecurity.org, 197

197

and perfect. 198

198

As you can see, we get redirected 199

199

to the smiley face instead of loading zsecurity.org. 200

200

Now, this will work against all websites 201

201

even if they use HTTPS. 202

202

As you saw earlier, zSecurity uses HTTPS 203

203

and it loaded over https by default. 204

204

The only websites that this will not work against 205

205

are websites that use HSTS 206

206

because again, as I mentioned before, 207

207

the browser has a list of these websites, 208

208

the list is stored locally on the target computer 209

209

so it doesn't send any requests 210

210

and it'll only load these websites over HTTPS. 211

211

So even though the attack will work, 212

212

the browser will refuse to load the website 213

213

that we are spoofing them to. 214

214

Now, as you can see, what we did so far 215

215

is not very useful. 216

216

All we did is just we showed a smiley face. 217

217

But DNS spoofing is very very useful 218

218

in so many scenarios. 219

219

You can use it, for example, 220

220

when someone is trying to go to a login page 221

221

and show them a fake page, 222

222

or if they're trying to go 223

223

to zSecurity, for example, 224

224

and then just show them another zSecurity website 225

225

with some malware embedded into it. 226

226

You can also use it to serve fake updates. 227

227

So whenever they have a software 228

228

that's gonna check for updates, 229

229

we can DNS spoof that request 230

230

and send them a fake update with a backdoor, 231

231

and we'll see that later on in the course. 232

232

So it's a really really handy skill 233

233

that can be used in so many scenarios.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.