I have a question on this. Why does annoying-ads.com DNS server sends the IP information as private IP address on second attempt why not on the first attempt itself ?
@funkykong90013 жыл бұрын
The first IP address is needed to download the malicious Javascript from the annoying-ads.com web server. Then the next DNS query points annoying-ads.com to an internal address, which then allows the Javascript to attack that internal IP address. If the first DNS query instead returned the internal IP address, then it wouldn't be able to fetch the malicious JS.
@BinaryAdventure3 жыл бұрын
@@funkykong9001 Also maybe it will use that first IP as a location of where to send information it finds maliciously on the local network, no?
@charlie3k2 жыл бұрын
@@BinaryAdventure I think this is the case. The video doesn't explicitly state it, but the attacker's original IP address needs to somehow be saved in order to traffic the router's responses back to the attacker.
@DavidEspinosa214 жыл бұрын
I did the test at the end (on Windows 10 Command Prompt) and all the returned IP addresses matched the IP addresses in 10:37, so does this mean I am in danger? The ones that matched those IP addresses were under "Non-authoritative answer"
@krkeeper-bh Жыл бұрын
A very instructive video, thank you very much. All the best