Rethinking the Security Threats of Stale DNS Glue Records
Yunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang, Xiang Li, Fan Shi, Chengxi Xu, Eihal Alowaisheq
摘要
The Domain Name System (DNS) fundamentally relies on glue records to provide authoritative nameserver IP addresses, enabling essential in-domain delegation. While previous studies have identified potential security risks associated with glue records, the exploitation of these records, especially in the context of out-domain delegation, remains unclear due to their inherently low trust level and the diverse ways in which resolvers handle them. This paper undertakes the first systematic exploration of the potential threats posed by DNS glue records, uncovering significant real-world security risks. We empirically identify that 23.18% of glue records across 1,096 TLDs are outdated yet still served in practice. More concerningly, through reverse engineering 9 mainstream DNS implementations (e.g., BIND 9 and Microsoft DNS), we reveal manipulable behaviors associated with glue records. The convergence of these systemic issues allows us to propose the novel threat model that could enable large-scale domain hijacking and denial-of-service attacks. Furthermore, our analysis determines over 193,558 exploitable records exist, placing more than 6 million domains at risk. Additional measurement studies on global open resolvers demonstrate that 90% of them use unvalidated and outdated glue records, including OpenDNS and Alibaba Cloud DNS. Our responsible disclosure has already prompted mitigation efforts by affected stakeholders. Microsoft DNS, PowerDNS, OpenDNS, and Alibaba Cloud DNS have acknowledged our reported vulnerability. In summary, this work highlights that glue records constitute a forgotten foundation of DNS architecture requiring renewed security prioritization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS InfrastructureYunyi Zhang, Mingming Zhang, Baojun Liu, Zhan Liu 等USENIX Security 2024 · 被引用 3 次
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 被引用 2 次
- Your Shield is My Sword: A Persistent Denial-of-Service Attack via the Reuse of Unvalidated Caches in DNSSEC ValidationShuhan Zhang, Shuai Wang, Li Chen, Dan Li 等USENIX Security 2025
- When Apps Outlive Vendors: Security Implications of IoT AbandonwareDayeon Kang, Elvis Yeboah-Duako, Sachin Thomas, Pubali DattaCCS 2026
- Misty Registry: An Empirical Study of Flawed Domain Registry OperationMingming Zhang, Yunyi Zhang, Baojun Liu, Haixin Duan 等USENIX Security 2025
它引用的顶会 Paper14
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 被引用 91 次
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel 等NDSS 2018 · 被引用 63 次
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng 等CCS 2020 · 被引用 62 次
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 被引用 33 次
相关 Paper
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi 等CCS 2020 · 被引用 19 次
- The Wolf of Name Street: Hijacking Domains Through Their NameserversThomas Vissers, Timothy Barron, Tom van Goethem, Wouter Joosen 等CCS 2017 · 被引用 44 次
- Robust or Risky: Measurement and Analysis of Domain Resolution DependencyShuhan Zhang, Shuai Wang, Dan LiINFOCOM 2024 · 被引用 3 次
- NXNSAttack: Recursive DNS Inefficiencies and VulnerabilitiesYehuda Afek, Anat Bremler-Barr, Lior ShafirUSENIX Security 2020
- Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain VerificationRuixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu 等USENIX Security 2026
