DNS Analyzer - Burp Suite: Difference between revisions
No edit summary |
No edit summary |
||
| Line 68: | Line 68: | ||
== References == | |||
<references> | |||
<ref name="Author">Gross, Stella. (2024). Custom screenshots created for the article and author of this article</ref> | |||
<references | </references> | ||
Step-by-Step Guide Reference: Inspired by Sec-Consult's blog post on DNS Analyzer: Finding DNS Vulnerabilities with Burp Suite (accessed on 11.12.2024, 12:27). | |||
[[Category:Pentesting]] | |||
Revision as of 11:29, 11 December 2024
WORK IN PROGRESS
A Burp Suite plugin for identifying DNS resolvers vulnerable to Kaminsky attacks in web applications.
Short rundown on what the Kaminsky attack is:
DNS cache poisoning involves injecting fake responses into a resolver's cache, redirecting users to malicious sites. In 2008, Dan Kaminsky exposed a flaw where static source ports and predictable transaction IDs made such attacks easier. Modern systems now randomize these elements, requiring attackers to guess 32 bits, making successful attacks far more challenging.[1]
This extension checks the randomness of:
UDP Source Port DNS Transaction ID Vulnerabilities arise when these elements are insufficiently random or predictable.
What happens behind the scene:
(bild einfügen)
Initiate Domain Resolution: The web application is forced to resolve a generated domain (e.g., 334jk47xssn7.oastify.com). DNS Query: The web application sends a query to the configured DNS resolver. Burp Collaborator: Logs the DNS query and returns an unmodified response. Analysis: Results are evaluated within the DNS Analyzer extension. Additional Tests: Can be triggered through actions like registration, password resets, or newsletter sign-ups. Requirement: A Burp Suite Professional license.
Step-by-Step Guide
The DNS Analyzer extension is available for installation directly from the BApp Store in Burp Suite. Navigate to Extensions > BApp Store > DNS Analyzer.
1. Select "Copy to Clipboard" to generate and copy a new Collaborator domain.
(Bild 2)
2. Initiate a DNS resolution for the generated domain. For instance, register a user with the email address test@[your Collaborator domain] on the target web application.
(Bild 3)
3. The table will continue to fill up as more interactions occur. If necessary, initiate additional DNS resolutions to meet the analysis threshold of 20 interactions.
(Bild 4)
4. Select a minimum of 20 interactions for analysis. The statistics and graphs will then be available for review in the results pane.
Analysis and Interpretation
he Kaminsky status is automatically generated by the DNS Analyzer after selecting 20+ interactions, categorizing results as POOR, GOOD, or GREAT based on metrics like:
Standard deviation: Measures distribution spread for source ports and DNS IDs. Direction bias: Detects upward/downward trends in distributions. Port difference (bits): Compares the range of ports/IDs. While these metrics provide a quick overview, scatter plots offer visual insights for identifying patterns machines might miss.
For instance, examining the two scatter plots below reveals no discernible patterns or predictability in the source port or DNS ID values.
The UDP source port values show no static distribution, and the DNS ID values are randomly distributed.
References
- ↑ Dan Kaminsky. (2008). Black ops 2008: It’s the end of the cache as we know it. In Black Hat USA Conference. IOActive, Inc. Presented at Black Hat USA 2008.
Cite error: <ref> tag with name "Author" defined in <references> is not used in prior text.
Step-by-Step Guide Reference: Inspired by Sec-Consult's blog post on DNS Analyzer: Finding DNS Vulnerabilities with Burp Suite (accessed on 11.12.2024, 12:27).