One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name Resolution
Fasheng Miao, Xiang Li, Changqing An, Wenbin Xu, Jilong Wang
Abstract
Domain names function as human-readable identifiers on the Internet, with characters serving as their essential building blocks. However, since the initial specification of domain names in 1983, the security implications of handling special characters within the domain name resolution process have remained largely overlooked. In this work, we conducted the first systematic study of special character handling logic in DNS, reviewing DNS RFCs and analyzing 31 widely-used DNS software implementations through source code review and gray-box testing. Our systematic analysis reveals two new DNS logic vulnerabilities arising from inconsistencies and silent handling behaviors, leading to two classes of attacks (four variants) that affect all DNS roles, including stub resolvers, forwarders, recursive resolvers, and authoritative nameservers. We name them the SHAR attack. Attackers can exploit these vulnerabilities to launch DNS cache poisoning and load balancing disruption attacks. Through comprehensive experiments, we validate the impact on the real world. All 31 tested mainstream DNS software implementations are vulnerable to SHAR. Notably, attackers can seize control of domain names, even the entire TLD (e.g.,. ir) or deceive victim resolvers to return invalid responses for legitimate queries, resulting in a persistent DoS effect. The SHAR attack can also enhance 10/13 well-known off-path DNS cache poisoning attacks (2002-2025). To further determine the impact in the wild, we test all DNS-related roles, including 21 mainstream Wi-Fi routers, 6 router OSes, 43 public DNS services, 883.5 K stable open DNS resolvers, Root servers, TLD servers, SLD servers, and 223.6 M domain names. The results show that the SHAR attack affects all tested Wi-Fi routers, router OSes, and public DNS services. In addition, we identify that resolvers, TLDs, and (5.6%) domain names are also vulnerable to the SHAR attack. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b9509580-5c04-4aa2-a5fc-7dab594ba161Related papers
- TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsXiang Li, Wei Xu, Baojun Liu, Mingming Zhang et al.S&P 2024 · 20 citations
- A Flushing Attack on the DNS CacheYehuda Afek, Anat Bremler-Barr, Shoham Danino, Yuval ShavittUSENIX Security 2024 · 2 citations
- Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersFenglu Zhang, Baojun Liu, Eihal Alowaisheq, Jianjun Chen et al.CCS 2023 · 3 citations
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
- XDRI Attacks - and - How to Enhance Resilience of Residential RoutersPhilipp Jeitner, Haya Schulmann, Lucas Teichmann, Michael WaidnerUSENIX Security 2022
