- What is Pharming ?
Pharming on the other hand poisons a DNS server by infusing false information into the DNS server, resulting in a user’s request being redirected elsewhere. Your browser, however will show you are at the correct Web site, which makes pharming a bit more serious and more difficult to detect.

- What is DNS :

- DNS Poisoning :

2. User wants to go the website www.nicebank.com and types the address in the web browser.
3. User’s computer queries the DNS server for the IP address of www.nicebank.com.
4. Since the DNS server has already been poisoned by the attacker, it returns the IP address of www.n1cebank.com to the user’s computer.
5. The user has now been fooled into visiting the fake website controlled by the attacker rather than the original www.nicebank.com website.
- Host Redirection :
Location:
%SystemRoot%\system32\drivers\etc\
Add an entry at the bottom where it says : 127.0.0.1 localhost
66.102.9.147 www.myspace.com
What it will do is redirect the person from myspace website to ip 66.102.9.147 which is the ip for google.com.Thus the attacker can manipulate the IP and take the victim towards any fake website.
- Prevent Pharming :
2. If you visit an SSL-enabled website, look out for this warning message window. If you get it, doubly check if the website you are visiting gave this message in earlier instances. Check if the URL is the same that you intend to go to.


Happy Hacking...Enjoy...
For educational purpose only...Do not misuse it...
No comments:
Post a Comment