Metasploit Bailiwick DNS Exploit Adds Domains
Overnight the Metasploit DNS exploit module continues to evolve to more devistating effect. Perhaps most importantly, a new module was introduced based on feedback from Cedric Blancher named Auxiliary::Spoof::Dns::BailiWickedDomain, which replaces the nameservers for a domain, allowing an attacker to redirect all traffic for the entire domain through them. Showcasing the ease of use of the Metasploit Framework, this entire exploit is written in 330 lines, including comments!
Further, a number of changes affect the efficiency of the module to speed up the attack. Metasploit will also now detect a cached entry, and wait until the cache expires to poision the entry.
With how quickly this module is improving, and it's current capability, if you're patching process wasn't already in a state of emergency, it should be.
