10/09/2008

Tool to poison non-patched DNS servers for any other messy upgrade process

07/28/08: ISR-evilgrade v1.0.0
It's is a modular framework that allow us to take advantage of poor upgrade implementations by injecting fake updates.
Demo - (Java plugin + Dan Kaminskys Dns vulnerability) = remote pwned

You need metasploit, but if you are a pentester, you knew that already

Someone believes that dns servers are always secure because they rely on the DNS of your ISP. In fact DNS is everywhere from your machine till the server of the website where you are going to and each of them has to be patched and secured. Period.

14:13 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment