All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records
Daiping Liu, Shuai Hao, Haining Wang
Abstract
In a dangling DNS record (Dare), the resources pointed to by the DNS record are invalid, but the record itself has not yet been purged from DNS. In this paper, we shed light on a largely overlooked threat in DNS posed by dangling DNS records. Our work reveals that Dare can be easily manipulated by adversaries for domain hijacking. In particular, we identify three attack vectors that an adversary can harness to exploit Dares. In a large-scale measurement study, we uncover 467 exploitable Dares in 277 Alexa top 10,000 domains and 52 edu zones, showing that Dare is a real, prevalent threat. By exploiting these Dares, an adversary can take full control of the (sub)domains and can even have them signed with a Certificate Authority (CA). It is evident that the underlying cause of exploitable Dares is the lack of authenticity checking for the resources to which that DNS record points. We then propose three defense mechanisms to effectively mitigate Dares with little human effort.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 62a903c2-e7fd-48ff-bd62-9680c694b2fdCited by top-tier papers29
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution PathBaojun Liu, Chaoyi Lu, Hai-Xin Duan, Ying Liu et al.USENIX Security 2018 · 67 citations
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel et al.NDSS 2018 · 63 citations
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang et al.CCS 2017 · 60 citations
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao et al.NDSS 2019 · 48 citations
Builds on3
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private InformationSuphannee Sivakorn, Iasonas Polakis, Angelos D. KeromytisS&P 2016 · 86 citations
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon et al.S&P 2016 · 76 citations
Related papers
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi et al.CCS 2020 · 19 citations
- Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain VerificationRuixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu et al.USENIX Security 2026
- Rethinking the Security Threats of Stale DNS Glue RecordsYunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang et al.USENIX Security 2024 · 9 citations
- Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS InfrastructureYunyi Zhang, Mingming Zhang, Baojun Liu, Zhan Liu et al.USENIX Security 2024 · 3 citations
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 22 citations
