dns spoof windows and netbios

From: Robin Wood (dninja@gmail.com)
Date: Mon Sep 25 2006 - 11:51:36 EDT


Hi
I'm trying to get dns spoofing working against windows XP. I'm running
dnsspoof from the dsniff package but it isn't working.

>From watching packets the dns question goes across to the fake dns
server which then replies, window then does a netbios nameserver
(NBNS) lookup on the same name. As dnsspoof doesn't handle NBNS
windows doesn't get a reply so it seems to ignore the fake result
given.

I've managed to spoof windows boxes before so I don't know why this
one is different. Anyone any ideas?

In case it matters, the network is 192.168.1.x with the fake dns
server on .1 routing all dns lookups to itself. Could it be that both
addresses are on the same subnet?

Thanks

Robin

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:57:00 EDT