TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets
Xiang Li, Wei Xu, Baojun Liu, Mingming Zhang, Zhou Li, Jia Zhang, Deliang Chang, Xiaofeng Zheng, Chuhan Wang, Jianjun Chen, Haixin Duan, Qi Li
摘要
DNS can be compared to a game of chess in that its rules are simple, yet the possibilities it presents are endless. While the fundamental rules of DNS are straightforward, DNS implementations can be extremely complex. In this study, we intend to explore the complexities and vulnerabilities in DNS response pre-processing by systematically analyzing DNS RFCs and DNS software implementations. We present the discovery of three new types of logic vulnerabilities, leading to the proposal of three novel attacks, namely the TuDoor attack. These attacks involve the use of malformed DNS response packets to carry out DNS cache poisoning, denial- of-service, and resource consuming attacks. By performing comprehensive experiments, we demonstrate the attack’s feasibility and significant real-world impacts of TUDOOR. In total, 24 mainstream DNS software, including BIND, PowerDNS, and Microsoft DNS, are affected by TuDoor. Attackers can instigate cache poisoning and denial-of-service attacks against vulnerable resolvers using a handful of crafted packets within 1 second or circumvent the query limit to deplete resolution resources (e.g., CPU). Besides, to determine the vulnerable resolver population in the wild, we collect and evaluate 16 popular Wi-Fi routers, 6 prevalent router OSes, 42 public DNS services, and around 1.8M open DNS resolvers. Our measurement results indicate that TUDOOR could exploit 7 routers (OSes), 18 public DNS services, and 424,652 (23.1%) open DNS resolvers. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors, and 18 of them, including BIND, Chrome, Cloudflare, and Microsoft, have acknowledged our findings and discussed mitigation solutions with us. Furthermore, 33 CVE IDs are assigned to our discovered vulnerabilities, and we provide an online detection tool as one of the mitigation measures. Our research highlights the urgent need for standardization of DNS response pre-processing logic to enhance the security of DNS.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper14
- TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersWei Xu, Xiang Li, Chaoyi Lu, Baojun Liu 等CCS 2023 · 被引用 15 次
- DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-ResponsesXiang Li, Dashuai Wu, Haixin Duan, Qi LiS&P 2024 · 被引用 14 次
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan 等USENIX Security 2024 · 被引用 13 次
- Rethinking the Security Threats of Stale DNS Glue RecordsYunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang 等USENIX Security 2024 · 被引用 9 次
- Cache Me, Catch You: Cache Related Security Threats in LLM Serving FrameworksXiangFan Wu, Lingyun Ying, Guoqiang Chen, Yacong Gu 等NDSS 2026 · 被引用 6 次
相关 Paper
- Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing VulnerabilitiesYuqi Qiu, Xiang Li, Zheli LiuS&P 2026
- One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name ResolutionFasheng Miao, Xiang Li, Changqing An, Wenbin Xu 等S&P 2026
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng 等CCS 2020 · 被引用 62 次
- The Maginot Line: Attacking the Boundary of DNS Caching ProtectionXiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang 等USENIX Security 2023
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 被引用 2 次
