Web Hack List

Collected research

Forgot password? Taking over user accounts Kaminsky style

Registering accounts on 146 real web applications with per-target subdomain e-mail addresses, then proxying the resulting MX lookups, to measure which applications still meet the preconditions for Kaminsky-style cache poisoning or IP-fragmentation attacks. Poisoning such a resolver redirects password-reset mail to the attacker and takes over accounts.

Record

Researcher
Timo Longin
Published by
SEC Consult
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Timo Longin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .