Collected research
Forgot password? Taking over user accounts Kaminsky style
Registering accounts on 146 real web applications with per-target subdomain e-mail addresses, then proxying the resulting MX lookups, to measure which applications still meet the preconditions for Kaminsky-style cache poisoning or IP-fragmentation attacks. Poisoning such a resolver redirects password-reset mail to the attacker and takes over accounts.
Record
- Researcher
- Timo Longin
- Published by
- SEC Consult
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Timo Longin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .