Lune

S&P2026Top-tier venue

One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name Resolution

Fasheng Miao, Xiang Li, Changqing An, Wenbin Xu, Jilong Wang

2026Year

Abstract

Domain names function as human-readable identifiers on the Internet, with characters serving as their essential building blocks. However, since the initial specification of domain names in 1983, the security implications of handling special characters within the domain name resolution process have remained largely overlooked. In this work, we conducted the first systematic study of special character handling logic in DNS, reviewing DNS RFCs and analyzing 31 widely-used DNS software implementations through source code review and gray-box testing. Our systematic analysis reveals two new DNS logic vulnerabilities arising from inconsistencies and silent handling behaviors, leading to two classes of attacks (four variants) that affect all DNS roles, including stub resolvers, forwarders, recursive resolvers, and authoritative nameservers. We name them the SHAR attack. Attackers can exploit these vulnerabilities to launch DNS cache poisoning and load balancing disruption attacks. Through comprehensive experiments, we validate the impact on the real world. All 31 tested mainstream DNS software implementations are vulnerable to SHAR. Notably, attackers can seize control of domain names, even the entire TLD (e.g.,. ir) or deceive victim resolvers to return invalid responses for legitimate queries, resulting in a persistent DoS effect. The SHAR attack can also enhance 10/13 well-known off-path DNS cache poisoning attacks (2002-2025). To further determine the impact in the wild, we test all DNS-related roles, including 21 mainstream Wi-Fi routers, 6 router OSes, 43 public DNS services, 883.5 K stable open DNS resolvers, Root servers, TLD servers, SLD servers, and 223.6 M domain names. The results show that the SHAR attack affects all tested Wi-Fi routers, router OSes, and public DNS services. In addition, we identify that 531.1K(60.1%)5 3 1. 1 \mathrm{K}(6 0. 1 \%) resolvers, 522(36.1%)5 2 2(3 6. 1 \%) TLDs, and 12.5M1 2. 5 \mathrm{M} (5.6%) domain names are also vulnerable to the SHAR attack. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get b9509580-5c04-4aa2-a5fc-7dab594ba161

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines