Security: DNS spoofing - are your nameservers good?
Posted: 06 May 2014, 23:57
DNS spoofing is a way for hackers to redirect web addresses to their servers by simply altering the IP.
So Google.com is IP 173.194.40.232. Computers do not understand "google.com" so they rely on the IP no. provided by nameservers.
it does not matter if you type 173.194.40.232 or "google.com" both will lead you to Google.com.
In 2008 there was a weaknes in the Domain Name Server system (DNS) that made it easy to replace the IP number so that "google.com" could theoretically be redirected to any computer.
Now this is really bad if you replace "google.com" with your Bank.
So how can we check if we are secure against this?
Simple:
Go here and click the button at the bottom of the page.
Since berserk often do not read documentations be warned that some routers may be crashed by this test - in that case you have a lousy router and should address the issue with your ISP. But the router will be fine and not harmed in any way - just power it off and on again.
Here are the data for my nameservers - I use OpenDns and DNScrypt:

So Google.com is IP 173.194.40.232. Computers do not understand "google.com" so they rely on the IP no. provided by nameservers.
it does not matter if you type 173.194.40.232 or "google.com" both will lead you to Google.com.
In 2008 there was a weaknes in the Domain Name Server system (DNS) that made it easy to replace the IP number so that "google.com" could theoretically be redirected to any computer.
Now this is really bad if you replace "google.com" with your Bank.
So how can we check if we are secure against this?
Simple:
Go here and click the button at the bottom of the page.
Since berserk often do not read documentations be warned that some routers may be crashed by this test - in that case you have a lousy router and should address the issue with your ISP. But the router will be fine and not harmed in any way - just power it off and on again.
Here are the data for my nameservers - I use OpenDns and DNScrypt: