Collected research
DNS Analyzer - Finding DNS vulnerabilities with Burp Suite
A Burp Suite extension that uses Burp Collaborator interactions to measure the UDP source port and DNS ID randomness of the resolver a web application uses, flagging resolvers still predictable enough for a Kaminsky cache-poisoning attack. An attacker who poisons such a resolver can redirect password-reset mail and take over accounts.
Record
- Researcher
- Timo Longin
- Published by
- SEC Consult
- Topic
- Other
In the archive
Related sources
- DNS Analyzer extension
- Earlier DNS analysis server
- Forgot password? Taking over user accounts Kaminsky style
- Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style
Tags
This page is the archive's own catalogue record. The research is the work of Timo Longin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .