DNS Analyzer - Burp Suite: Difference between revisions

From Elvis Wiki
No edit summary
No edit summary
Line 4: Line 4:
A Burp Suite plugin for identifying DNS resolvers vulnerable to Kaminsky attacks in web applications.
A Burp Suite plugin for identifying DNS resolvers vulnerable to Kaminsky attacks in web applications.


Short rundown on what the Kaminsky attack is:
DNS cache poisoning involves injecting fake responses into a resolver's cache, redirecting users to malicious sites. In 2008, Dan Kaminsky exposed a flaw where static source ports and predictable transaction IDs made such attacks easier. Modern systems now randomize these elements, requiring attackers to guess 32 bits, making successful attacks far more challenging.<ref name="Kaminsky2008">Dan Kaminsky. (2008). Black ops 2008: It’s the end of the cache as we know it. In Black Hat USA Conference. IOActive, Inc. Presented at Black Hat USA 2008.</ref>




<references /> [[Category:Pentesting]]
<references /> [[Category:Pentesting]]

Revision as of 11:11, 11 December 2024

WORK IN PROGRESS


A Burp Suite plugin for identifying DNS resolvers vulnerable to Kaminsky attacks in web applications.

Short rundown on what the Kaminsky attack is:

DNS cache poisoning involves injecting fake responses into a resolver's cache, redirecting users to malicious sites. In 2008, Dan Kaminsky exposed a flaw where static source ports and predictable transaction IDs made such attacks easier. Modern systems now randomize these elements, requiring attackers to guess 32 bits, making successful attacks far more challenging.[1]


  1. Dan Kaminsky. (2008). Black ops 2008: It’s the end of the cache as we know it. In Black Hat USA Conference. IOActive, Inc. Presented at Black Hat USA 2008.