Week 9
Week 9
Lecture Objectives
• Explain ARP, DNS, and DHCP protocols and how they can be
manipulated.
• Attacker sends fake ARP replies to associate their MAC address with IP
of a legitimate device (e.g., gateway).
• arpspoof: CLI tool from dsniff package for injecting fake ARP
responses.
• Flush DNS cache regularly and use encrypted DNS (DoH or DoT).
• Launch Bettercap:
• Steps:
1.Enable IP forwarding.
o Malicious DNS
• Run Responder:
• Filters:
o eth.addr == xx:xx:xx:xx:xx:xx