Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1 1
Now in this lecture, 2
2
we're going to learn what DNS spoofing is 3
3
and how to perform it. 4
4
DNS is a server that converts domain names, 5
5
such as google.com, to the IP of the server 6
6
that is hosting this website. 7
7
So, when you type google.com in your web browser, 8
8
the request goes to a DNS server, 9
9
the server responds with the IP 10
10
where google.com files are stored, 11
11
and the browser will load the website 12
12
from this IP. 13
13
Now, when we are the man in the middle, 14
14
the request for google.com 15
15
will pass through us first 16
16
before it goes to the DNS server. 17
17
Therefore, instead of giving the IP 18
18
of the server that is hosting google.com, 19
19
we can actually give any IP we want. 20
20
So we can redirect them to a fake website 21
21
with a backdoor or with evil code, 22
22
hijack software updates and so much more. 23
23
We'll actually have examples on this 24
24
in future lectures but for now 25
25
let's see how we can run 26
26
a basic DNS spoofing attack, 27
27
in which we redirect requests 28
28
from a specific website to our own website 29
29
or our own web server. 30
30
Now before we run bettercap, 31
31
let's decide on where to redirect our target to. 32
32
So, we can redirect them to any website we want, 33
33
for example when someone requests google.com, 34
34
we can redirect them to Yahoo. 35
35
But what I want to do is 36
36
I want to redirect them to my own website, 37
37
to a local website that I'm gonna start on Kali. 38
38
Kali comes with its own web server 39
39
so we can actually use it as a website 40
40
and to do this, all we have to do 41
41
is just start the web server 42
42
so we're gonna do service apache2 start. 43
43
So apache2 is the name of the web server 44
44
and we're saying that we want to start this service. 45
45
If I hit Enter, we see no errors, 46
46
which means that the server is working now. 47
47
And to access this website, 48
48
to access this server, 49
49
we have to go to Kali's IP. 50
50
So as you know, to get our IP we can do ifconfig, 51
51
and we can see our IP is 10.0.2.15. 52
52
So if I just go to a web browser 53
53
and go to 10.0.2.15, 54
54
you'll see I'll get the default page of this website. 55
55
Now, the pages for this default web site 56
56
is stored in var/www/html. 57
57
So I'm gonna open my file manager 58
58
and I'm gonna click here on the title bar, 59
59
press forward slash to open it, 60
60
and we're gonna go to var/www/html, 61
61
and as you can see, these are the files 62
62
for this website. 63
63
So if you want to install a fake website 64
64
or any type of website, all you have to do 65
65
is just put its files in here. 66
66
Now, index.html is the file 67
67
that gets loaded here by default. 68
68
So this is what you see in here. 69
69
So I'm actually gonna right-click it. 70
70
I'm gonna open it with another application. 71
71
I'm gonna select my Text Editor. 72
72
This will open the html code for me, 73
73
and I'm actually just gonna remove this, 74
74
and I'll just put a smiley face. 75
75
Like I said, we're just doing this for testing, 76
76
so just showing you which files get loaded by default 77
77
and where you can actually put a website 78
78
if you wanted to host a proper website here. 79
79
So, I'm gonna go back here and if I refresh the page, 80
80
you can see we get the smiley face in here. 81
81
Now that's perfect. 82
82
Right now we still haven't executed 83
83
our DNS spoofing attack 84
84
but what I want to do is, 85
85
when my target tries to go to a specific website 86
86
I'm gonna redirect them to this page 87
87
that shows the smiley face. 88
88
So let's go to the target machine first 89
89
and let's go to our target website. 90
90
I'm gonna do this against my own website, 91
91
zsecurity.org. 92
92
So if you load this website, 93
93
you'll see we'll get an actual security website 94
94
with a number of topics and all that kind of stuff. 95
95
Basically the website is working as expected. 96
96
Now let's go ahead and run this attack. 97
97
So I'm gonna go to bettercap. 98
98
I'm gonna run it using the exact same command 99
99
that we've been using so far. 100
100
So we're just doing bettercap 101
101
with the interface with the spoof caplet 102
102
so we can intercept data and modify it 103
103
as it's flowing through our computer. 104
104
And as you can see, it's running with no errors 105
105
so that's all good. 106
106
Now, the module that we want to use 107
107
is called dns spoof. 108
108
So if I do help right now, 109
109
you can see it right here, 110
110
it's called dns spoof and it's not running. 111
111
And as usual, if we don't know how to use a module, 112
112
all we have to do is do help 113
113
followed by the module name 114
114
and in this case it's dns spoof. 115
115
And as you can see we get all the options 116
116
that we can set for this module. 117
117
First option being the dns spoof address. 118
118
This is the address that the user 119
119
will be redirected to. 120
120
So if you want to redirect them 121
121
to another website, you have to put 122
122
the IP of this other website here. 123
123
In my case I want to redirect them 124
124
to my local website, 125
125
to the website that we have here, 126
126
which is running at 10.0.2.15. 127
127
Therefore, I'm not gonna have to modify this 128
128
because by default this is set 129
129
to the IP of my interface. 130
130
The next thing that we want to modify 131
131
is the dns.spoof.all. 132
132
We want to set this to true 133
133
so that bettercap responds 134
134
to any DNS request. 135
135
So just like any other option within bettercap 136
136
to change its value, we have to do set, 137
137
followed by the option name 138
138
that we want to modify, 139
139
and in this case it's dns.spoof.all, 140
140
and we want to set this to true. 141
141
Sorry, this is all being produced by the sniffer. 142
142
The next option that we want to set 143
143
is the dns.spoof.domains. 144
144
This will specify the domains 145
145
that we want to target, 146
146
that we want to spoof. 147
147
And as mentioned, we can use a comma 148
148
to separate more than one domain. 149
149
And as you know, we want to target zsecurity.org 150
150
and we want to redirect that 151
151
to our own website running on Kali. 152
152
So, we need to change this option right here, 153
153
dns.spoof.domains, and again, 154
154
we're gonna do this by doing set, 155
155
the option name, which is dns.spoof.domains, 156
156
and we're gonna set this to zsecurity.org. 157
157
As mentioned in the option 158
158
we can use the comma 159
159
to specify more than one domain 160
160
and the other domain that I want to specify 161
161
is star .zsecurity.org. 162
162
So the star right here is a wildcard 163
163
and it basically means that I want to target 164
164
any subdomain .zsecurity.org. 165
165
So I'm gonna hit Enter 166
166
and we don't see any errors 167
167
so everything is set as expected. 168
168
And all we need to do now 169
169
is start the dns spoof and to do this, 170
170
we just need to run dns.spoof 171
171
on exactly the same way that we start 172
172
any other module. 173
173
I'm gonna hit Enter and this should be running right now 174
174
and as you can see, it's telling us 175
175
that it's going to spoof zsecurity.org 176
176
to this IP, which is again, this is our IP, 177
177
we verified this using the ifconfig command. 178
178
And keep in mind, we actually did not have 179
179
to give bettercap this IP. 180
180
It got it automatically. 181
181
It's also telling us that the other target 182
182
is star .zsecurity.org 183
183
and it'll be spoofed to this. 184
184
Now, let's go to the target machine 185
185
and test this and before you test this, 186
186
please keep in mind you might need to wait 187
187
for a minute or two for the changes to propagate. 188
188
Also, if you just loaded this website, 189
189
just like I did right now, 190
190
it's a good idea to remove all your browsing data. 191
191
You won't have to do this in real-life scenarios 192
192
unless the target person is constantly loading 193
193
the same page, which doesn't happen a lot. 194
194
But if the target person goes ahead 195
195
and browses a few websites, 196
196
comes back to zsecurity.org, 197
197
and perfect. 198
198
As you can see, we get redirected 199
199
to the smiley face instead of loading zsecurity.org. 200
200
Now, this will work against all websites 201
201
even if they use HTTPS. 202
202
As you saw earlier, zSecurity uses HTTPS 203
203
and it loaded over https by default. 204
204
The only websites that this will not work against 205
205
are websites that use HSTS 206
206
because again, as I mentioned before, 207
207
the browser has a list of these websites, 208
208
the list is stored locally on the target computer 209
209
so it doesn't send any requests 210
210
and it'll only load these websites over HTTPS. 211
211
So even though the attack will work, 212
212
the browser will refuse to load the website 213
213
that we are spoofing them to. 214
214
Now, as you can see, what we did so far 215
215
is not very useful. 216
216
All we did is just we showed a smiley face. 217
217
But DNS spoofing is very very useful 218
218
in so many scenarios. 219
219
You can use it, for example, 220
220
when someone is trying to go to a login page 221
221
and show them a fake page, 222
222
or if they're trying to go 223
223
to zSecurity, for example, 224
224
and then just show them another zSecurity website 225
225
with some malware embedded into it. 226
226
You can also use it to serve fake updates. 227
227
So whenever they have a software 228
228
that's gonna check for updates, 229
229
we can DNS spoof that request 230
230
and send them a fake update with a backdoor, 231
231
and we'll see that later on in the course. 232
232
So it's a really really handy skill 233
233
that can be used in so many scenarios.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.