OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-Disclosure] [Research Paper] DNS Cache Snooping

From: Luis Grangeia (luis.grangeiasidestep.pt)
Date: Thu Apr 22 2004 - 11:29:31 CDT


Hi,

I have written a research paper on a relatively ignored DNS issue known
as DNS Cache Snooping. This issue allows one, for instance, to query a
DNS cache to verify if a certain site has been accessed or if an email
was recently sent to a given domain.

Abstract and link below. Reader feedback and constructive criticism is
welcome and appreciated.

Available at

http://community.sidestep.pt/~luis/DNS-Cache-Snooping/

ABSTRACT

This research paper presents a technical overview of the technique known
as DNS cache snooping. Firstly, a brief introduction to DNS is made
followed by a discussion on common misconceptions regarding DNS
sub-systems. Then this relatively unknown technique is introduced,
followed by a field study to assert the overall exposure of the Internet
to this threat. Also, a set of devised abuse scenarios that rely on
cache snooping is presented. This paper concludes with recommendations
on how to reduce exposure to this problem, including proposed changes to
the BIND DNS server implementation.

Regards,

--
Luis Grangeia, GSNA
http://community.sidestep.pt/~luis/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html