DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels
Keyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng, Youjun Huang, Haixin Duan
Abstract
In this paper, we report a series of flaws in the software stack that leads to a strong revival of DNS cache poisoning --- a classic attack which is mitigated in practice with simple and effective randomization-based defenses such as randomized source port. To successfully poison a DNS cache on a typical server, an off-path adversary would need to send an impractical number of spoofed responses simultaneously guessing the correct source port (16-bit) and transaction ID (16-bit). Surprisingly, we discover weaknesses that allow an adversary to "divide and conquer'' the space by guessing the source port first and then the transaction ID (leading to only spoofed responses). Even worse, we demonstrate a number of ways an adversary can extend the attack window which drastically improves the odds of success. The attack affects all layers of caches in the DNS infrastructure, such as DNS forwarder and resolver caches, and a wide range of DNS software stacks, including the most popular BIND, Unbound, and dnsmasq, running on top of Linux and potentially other operating systems. The major condition for a victim being vulnerable is that an OS and its network is configured to allow ICMP error replies. From our measurement, we find over 34% of the open resolver population on the Internet are vulnerable (and in particular 85% of the popular DNS services including Google's 8.8.8.8). Furthermore, we comprehensively validate the proposed attack with positive results against a variety of server configurations and network conditions that can affect the success of the attack, in both controlled experiments and a production DNS resolver (with authorization).
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6619fae9-63ea-40ae-aa56-547be9590f49Cited by top-tier papers42
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 33 citations
- Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNSPhilipp Jeitner, Haya SchulmannUSENIX Security 2021 · 32 citations
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 22 citations
- From IP to transport and beyond: cross-layer attacks against applicationsTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerSIGCOMM 2021 · 14 citations
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
Related papers
- DNS Cache Poisoning Like it’s 2006Omer Ben-Simhon, Amit KleinUSENIX Security 2026
- The Maginot Line: Attacking the Boundary of DNS Caching ProtectionXiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang et al.USENIX Security 2023
- RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday ParadoxXiang Li, Mingming Zhang, Zuyao Xu, Fasheng Miao et al.CCS 2025
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 2 citations
- Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding DevicesXiaofeng Zheng, Chaoyi Lu, Jian Peng, Qiushi Yang et al.USENIX Security 2020
