Client-side Name Collision Vulnerability in the New gTLD Era: A Systematic Study
Qi Alfred Chen, Matthew Thomas, Eric Osterweil, Yulong Cao, Jie You, Zhuoqing Morley Mao
Abstract
The recent unprecedented delegation of new generic top-level domains (gTLDs) has exacerbated an existing, but fallow, problem called name collisions. One concrete exploit of such problem was discovered recently, which targets internal namespaces and enables Man in the Middle (MitM) attacks against end-user devices from anywhere on the Internet. Analysis of the underlying problem shows that it is not speci c to any single service protocol, but little attention has been paid to understand the vulnerability status and the defense solution space at the service level. In this paper, we perform the rst systematic study of the robustness of internal network services under name collision attacks. We rst perform a measure study and uncover a wide spectrum of services a ected by the name collision problem. We then collect their client implementations and systematically analyze their vulnerability status under name collision attacks using dynamic analysis. Out of the 48 identi ed exposed services, we nd that nearly all (45) of them expose vulnerabilities in popular clients. To demonstrate the severity, we construct exploits and nd a set of new name collision attacks with severe security implications including MitM attacks, internal or personal document leakage, malicious code injection, and credential theft. We analyze the causes, and nd that the name collision problem broadly breaks common security assumptions made in today's service client software. Leveraging the insights from our analysis, we propose multiple service software level solutions, which enables the victim services to actively defend against name collision attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19ad0d09-abf3-4d61-8344-8abde6952da7Cited by top-tier papers2
- Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution PathBaojun Liu, Chaoyi Lu, Hai-Xin Duan, Ying Liu et al.USENIX Security 2018 · 67 citations
- The Maginot Line: Attacking the Boundary of DNS Caching ProtectionXiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang et al.USENIX Security 2023
Builds on2
- Staying Secure and Unprepared: Understanding and Mitigating the Security Risks of Apple ZeroConfXiaolong Bai, Luyi Xing, Nan Zhang, XiaoFeng Wang et al.S&P 2016 · 33 citations
- MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD EraQi Alfred Chen, Eric Osterweil, Matthew Thomas, Zhuoqing Morley MaoS&P 2016 · 25 citations
Related papers
- Unsafe at Any Copy: Name Collisions from Mixing Case SensitivitiesAditya Basu, John Sampson, Zhiyun Qian, Trent JaegerFAST 2023 · 4 citations
- Investigations of Top-Level Domain Name Collisions in Blockchain Naming ServicesDaiki Ito, Yuta Takata, Hiroshi Kumagai, Masaki KamizonoWWW 2024 · 7 citations
- Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain VerificationRuixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu et al.USENIX Security 2026
- Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost WebsitesTakuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya MoriNDSS 2020
- Measuring and Mitigating the Risk of IP Reuse on Public CloudsEric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke et al.S&P 2022 · 22 citations
