Web Hack List

Collected research

DNS Cache Poisoning Attack: Resurrections with Side Channels

Novel side channels in the Linux kernel let an off-path attacker use ICMP fragment-needed and redirect messages to scan a DNS resolver's UDP ephemeral port, because the shared next-hop exception cache leaks which port is open. Derandomising the port defeats the main defence against DNS cache poisoning, letting forged records be injected into resolvers such as BIND, Unbound and dnsmasq.

Record

Researcher
Keyu Man, Xin'an Zhou and Zhiyun Qian
Published by
cs.ucr.edu
Format
Whitepaper
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Keyu Man, Xin'an Zhou and Zhiyun Qian, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .