Powered By Blogger

Sunday, June 6, 2010

Practical 4.3 Hosts file attack

This time would be about hosts file attack....this happens by substituting a fraudulent IP address. Attackers can target local hosts file and create new entries to redirect users to their fraudulent website.... So I will be showing an easy example of how they do the redirecting....

First check out any 2 websites of your choice.....in this case I will be choosing Course Technology Web site and Google.... confirm the 2 URLs are working and make sure you know any one of the website's IP address....

After meeting these requirements you are now ready to attack your own hosts file>>>>>

First, search for "Notepad" in your start menu, right-click it and choose "Run as administrator"... As shown in the screenshot below


After which, when your notepad opens.....click on the File tab and choose "Open"; next navigate to your file C:\windows\system32\drivers\etc\hosts and open it....
At the end of the file enter the IP address of google,74.125.47.99 as shown in the red bracket in the screenshot below>>> Then press the Tab button and type the URL www.course.com as shown in the green bracket in the screenshot below....

After typing the IP address and another website's URL in.... go to File and click Save... Now,,, to test out whether it works... Open your web browser and type in the same URL that you have typed into the green bracket ...

So for my case initally the link www.course.com is suppose to bring me to the webpage as shown in the screenshot below>>>>
But after doing those editing in the notepad, after I entered the URL www.course.com into the web browser.... it will bring me to the webpage of google as shown in the screenshot below....





And if this happens that means that you have successfully attack your own hosts file....Congrats.... Now to revert it back to normal just delete what you have just entered and Save the notepad.... After you have done this, everything will revert back to normal.....
REFLECTIONS!!!!!!!
Through this practical, I have learnt that DNS stands for Domain Name System... Its purpose is to name resolution within your domain as well as outside of your domain.... And the purpose of substituting a fraudulent IP address in the DNS or the hosts file is so that when a user enters a specific URL, he/she is redirected to the fraudulent website.....

No comments:

Post a Comment