DNS injection code base on ruby have be published,We will face a new chanllenge on website security

本文讨论了一种名为'dnsinjectcode'的DNS注入攻击手段,并分析了其潜在危害。作者通过跟踪发现该注入代码位于Metasploit项目的某一模块中,警示网络信息中心必须采取措施应对这一漏洞,以防网站用户名及密码被恶意窃取。

Today ,I see on the youkuaiyun.com ,a new article about the 'dns inject code ' abstract me.I follow it ,and I find the injection code in http://metasploit.com/dev/trac/browser/framework3/trunk/modules/auxiliary/spoof/dns/baliwicked_host.rb?rev=5579

So I think our network information center must have some solution to this hole , otherwise our website's username and password is oberviously become useless ,the hack will use this code to poison the dns server ,then direct we to an fake website have the same UI ,then we input the username and password ,the hacker will cat it .Although the code line is just for 332,bu  the nic department must very  recognition this event.

 

 

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值