Web Hack List

Collected research

DNS Analyzer - Finding DNS vulnerabilities with Burp Suite

A Burp Suite extension that uses Burp Collaborator interactions to measure the UDP source port and DNS ID randomness of the resolver a web application uses, flagging resolvers still predictable enough for a Kaminsky cache-poisoning attack. An attacker who poisons such a resolver can redirect password-reset mail and take over accounts.

Record

Researcher
Timo Longin
Published by
SEC Consult
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Timo Longin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .