Collected research
Windows DNS Server Cache Poisoning
Windows DNS Server uses a static UDP source port and a structured transaction ID. CNAME chains advance its counter to a state where the next ID has only eight possible values, enabling cache poisoning after a browser-triggered lookup. The paper derives the predictor, explains forwarding variants and includes a Perl prediction script.
Record
- Researcher
- Amit Klein
- Published by
- Trusteer
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .