Web Hack List

Top 10 winner

DNS poisoning via Port Exhaustion

Announces a whitepaper on poisoning stub resolvers by exhausting the source ports available to a client, collapsing DNS query entropy. Two flaws are disclosed: a remote variant driven by Java applets (CVE-2011-3552, CVE-2010-4448) yielding cookie, NTLM and clipboard theft and firewall bypass, and a local variant letting an unprivileged Windows user poison other users.

Record

Researcher
Roee Hay and Yair Amit
Published by
IBM Application Security Insider
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Roee Hay and Yair Amit, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .