Book Image

Practical Network Scanning

By : Ajay Singh Chauhan
Book Image

Practical Network Scanning

By: Ajay Singh Chauhan

Overview of this book

Network scanning is the process of assessing a network to identify an active host network; same methods can be used by an attacker or network administrator for security assessment. This procedure plays a vital role in risk assessment programs or while preparing a security plan for your organization. Practical Network Scanning starts with the concept of network scanning and how organizations can benefit from it. Then, going forward, we delve into the different scanning steps, such as service detection, firewall detection, TCP/IP port detection, and OS detection. We also implement these concepts using a few of the most prominent tools on the market, such as Nessus and Nmap. In the concluding chapters, we prepare a complete vulnerability assessment plan for your organization. By the end of this book, you will have hands-on experience in performing network scanning using different tools and in choosing the best tools for your system.
Table of Contents (19 chapters)
Title Page
Packt Upsell
Contributors
Preface
Index

DNS vulnerabilities 


DNS continues to be a very attractive target for hackers and a very important piece of network from a user's point of view. We use it seamlessly almost every time we hit a web page or application throughout a day, without even knowing that it exists.

DNS provides a way to resolve the IP address of any host on the internet with directory services.

How does DNS work?

A host sends a DNS query request to a DNS server and, in response, gets the IP address 1.1.1.1 for  www.abc.com. The host can now make a direct request to www.abc.com using  the IP address: 

DNS protocol attacks

DNS spoofing or DNS cache poisoning: DNS spoofing occurs when particular DNS server records are altered to redirect traffic to the attacker. This redirection of traffic allows the attacker to steal data because it is hard for users to recognize the difference between an actual web page and a false web page.

In this example, users are trying to get the IP address for a real web server which is 1.1.1.1 but...