USENIX Security2021Top-tier venue
Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS
Philipp Jeitner, Haya Schulmann
Abstract
The traditional design principle for Internet protocols indicates: “Be strict when sending and tolerant when receiv-ing” [RFC1958], and DNS is no exception to this. The transparency of DNS in handling the DNS records, also standardised specifically for DNS [RFC3597], is one of the key features that made it such a popular platform facilitating a constantly increasing number of new applications. An application simply creates a new DNS record and can instantly start dis-tributing it over DNS without requiring any changes to the DNS servers and platforms. Our Internet wide study confirms that more than 1.3M (96% of tested) open DNS resolvers are standard compliant and treat DNS records transparently. In this work we show that this ‘transparency’ introduces a severe vulnerability in the Internet: we demonstrate a new method to launch string injection attacks by encoding malicious payloads into DNS records. We show how to weaponise such DNS records to attack popular applications. For instance, we apply string injection to launch a new type of DNS cache poisoning attack, which we evaluated against a population of open resolvers and found 105K to be vulnerable. Such cache poisoning cannot be prevented with common setups of DNSSEC. Our attacks apply to internal as well as to public services, for instance, we reveal that all eduroam services are vulnerable to our injection attacks, allowing us to launch exploits ranging from unauthorised access to eduroam networks to resource starvation. Depending on the application, our attacks cause system crashes, data corruption and leak-age, degradation of security, and can introduce remote code execution and arbitrary errors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c2a3eac0-97fd-4452-89fc-7266f0c3c496Cited by top-tier papers13
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 33 citations
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 22 citations
- From IP to transport and beyond: cross-layer attacks against applicationsTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerSIGCOMM 2021 · 14 citations
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
- Rethinking the Security Threats of Stale DNS Glue RecordsYunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang et al.USENIX Security 2024 · 9 citations
Builds on4
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann et al.CCS 2018 · 71 citations
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding DevicesXiaofeng Zheng, Chaoyi Lu, Jian Peng, Qiushi Yang et al.USENIX Security 2020
- Encrypted DNS -> Privacy? A Traffic Analysis PerspectiveSandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez et al.NDSS 2020
Related papers
- XDRI Attacks - and - How to Enhance Resilience of Residential RoutersPhilipp Jeitner, Haya Schulmann, Lucas Teichmann, Michael WaidnerUSENIX Security 2022
- TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsXiang Li, Wei Xu, Baojun Liu, Mingming Zhang et al.S&P 2024 · 20 citations
- One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name ResolutionFasheng Miao, Xiang Li, Changqing An, Wenbin Xu et al.S&P 2026
- A Flushing Attack on the DNS CacheYehuda Afek, Anat Bremler-Barr, Shoham Danino, Yuval ShavittUSENIX Security 2024 · 2 citations
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 2 citations
