Contents

Old School On-target NBNS Spoofing - Part 2

Contents

So it turns out that Windows Firewall talks IP addresses just like any other firewall, so if you configure FakeNetBIOSNS to tell everyone that the IP address for whatever they looked up is YOUR IP, guess what, no need to bypass the spoof filters ;-) Happy Rob!

1
2
3
$ cat nbns.ini   
PROJECTMENTOR WPAD 172.16.10.207  
PROJECTMENTOR FILESHARE 173.26.10.207

/images/postimages/201209_nbns_1.png

Results in:

/images/postimages/201209_nbns_2.png

Game ON!