DNS Analyzer - Burp Suite: Difference between revisions

From Elvis Wiki
Line 70: Line 70:
     <ul>
     <ul>
       <li>Select "Copy to Clipboard" to generate and copy a new Collaborator domain.</li>
       <li>Select "Copy to Clipboard" to generate and copy a new Collaborator domain.</li>
       [[File:Bild_2.png|thumb|none|600px|Generating a Collaborator Domain]]
       [[File:Bild_2.png|thumb|none|600px|Generating a Collaborator Domain <ref name="Author"/>]]
     </ul>
     </ul>
   </li>
   </li>
Line 77: Line 77:
     <ul>
     <ul>
       <li>Initiate a DNS resolution for the generated domain. For example, register a user with the email address test@[your Collaborator domain] on the target web application.</li>
       <li>Initiate a DNS resolution for the generated domain. For example, register a user with the email address test@[your Collaborator domain] on the target web application.</li>
       [[File:Bild_3.png|thumb|none|600px|Initiating DNS Resolution]]
       [[File:Bild_3.png|thumb|none|600px|Initiating DNS Resolution <ref name="Author"/>]]
     </ul>
     </ul>
   </li>
   </li>
Line 84: Line 84:
     <ul>
     <ul>
       <li>The table will continue to fill up as more interactions occur. If necessary, initiate additional DNS resolutions to meet the analysis threshold of 20 interactions.</li>
       <li>The table will continue to fill up as more interactions occur. If necessary, initiate additional DNS resolutions to meet the analysis threshold of 20 interactions.</li>
       [[File:Bild_4.png|thumb|none|600px|Monitoring Interactions]]
       [[File:Bild_4.png|thumb|none|600px|Monitoring Interactions <ref name="Author"/>]]
     </ul>
     </ul>
   </li>
   </li>
Line 91: Line 91:
     <ul>
     <ul>
       <li>Select a minimum of 20 interactions for analysis. The statistics and graphs will then be available for review in the results pane.</li>
       <li>Select a minimum of 20 interactions for analysis. The statistics and graphs will then be available for review in the results pane.</li>
       [[File:Bild_4.png|thumb|none|600px|Analysis Results Pane]]
       [[File:Bild_4.png|thumb|none|600px|Analysis Results Pane <ref name="Author"/>]]
     </ul>
     </ul>
   </li>
   </li>
</ol>
</ol>


== Analysis and Interpretation ==
== Analysis and Interpretation ==

Revision as of 19:09, 11 December 2024

WORK IN PROGRESS

A Burp Suite plugin for identifying DNS resolvers vulnerable to Kaminsky attacks in web applications.

Short rundown on what the Kaminsky attack is:

DNS cache poisoning involves injecting fake responses into a resolver's cache, redirecting users to malicious sites. In 2008, Dan Kaminsky exposed a flaw where static source ports and predictable transaction IDs made such attacks easier. Modern systems now randomize these elements, requiring attackers to guess 32 bits, making successful attacks far more challenging.[1]

This extension checks the randomness of:

  • UDP Source Port: Evaluates the randomness of source port values.
  • DNS Transaction ID: Measures the predictability of transaction IDs.

Vulnerabilities arise when these elements are insufficiently random or predictable.


What Happens?

File:Bild 1.png
[2]
  1. Initiate Domain Resolution:
    • The web application is forced to resolve a generated domain (e.g., 334jk47xssn7.oastify.com).
  2. DNS Query:
    • The web application sends a query to the configured DNS resolver.
  3. Burp Collaborator:
    • Logs the DNS query and returns an unmodified response.
  4. Analysis
    • Results are evaluated within the DNS Analyzer extension.
  5. Additional Tests
    • Can be triggered through actions like registration, password resets, or newsletter sign-ups.
Requirement: A Burp Suite Professional license.

Step-by-Step Guide

  1. Install DNS Analyzer Extension:
    • The DNS Analyzer extension is available for installation directly from the BApp Store in Burp Suite. Navigate to Extensions > BApp Store > DNS Analyzer.
  2. Generate Collaborator Domain:
    • Select "Copy to Clipboard" to generate and copy a new Collaborator domain.
    • File:Bild 2.png
      Generating a Collaborator Domain [2]
  3. Initiate DNS Resolution:
    • Initiate a DNS resolution for the generated domain. For example, register a user with the email address test@[your Collaborator domain] on the target web application.
    • File:Bild 3.png
      Initiating DNS Resolution [2]
  4. Monitor Interactions:
    • The table will continue to fill up as more interactions occur. If necessary, initiate additional DNS resolutions to meet the analysis threshold of 20 interactions.
    • File:Bild 4.png
      Monitoring Interactions [2]
  5. Review Analysis Results:
    • Select a minimum of 20 interactions for analysis. The statistics and graphs will then be available for review in the results pane.
    • File:Bild 4.png
      Analysis Results Pane [2]

Analysis and Interpretation

Kaminsky status:

The Kaminsky status is automatically generated by the DNS Analyzer after selecting 20+ interactions, categorizing results as POOR, GOOD, or GREAT based on metrics like:

  • Standard deviation: Measures the spread of distribution for source ports and DNS IDs.
  • Direction bias: Detects trends (upward or downward) in the distributions.
  • Port difference (bits): Compares the range of source ports and DNS IDs.

Scatter plots:

  • Visual insights: Scatter plots provide additional insights, enabling identification of patterns that automated analysis might miss.
  • Example:
    • The UDP source port values show no static distribution, indicating randomness.
    • The DNS ID values appear randomly distributed, with no observable clustering or predictability.
File:Bild 5.png
Scatter Plot Analysis [2]

References

  1. Dan Kaminsky. (2008). Black ops 2008: It’s the end of the cache as we know it. In Black Hat USA Conference. IOActive, Inc. Presented at Black Hat USA 2008.
  2. 2.0 2.1 2.2 2.3 2.4 2.5 Gross, Stella. (2024). Custom screenshots created for the article and author of this article

Step-by-Step Guide Reference: Inspired by Sec-Consult's blog post on DNS Analyzer: Finding DNS Vulnerabilities with Burp Suite (accessed on 11.12.2024, 12:27).