Site Archives DNS spoofing

Multi-Vendor DNS Spoofing Vulnerability

Posted on July 9th, 2008

GSA Reference Number: AD080709-01

Simply Put: Recently, multiple vendors have released patches to address a vulnerability in the DNS protocol.  DNS is used for resolving host names and web addresses to IP addresses on the Internet.  DNS servers will send out queries to other DNS servers when they receive a request for a host not stored in their database.  When that happens, an attacker can respond to the request with a specially crafted packet with a malicious IP address.  Since DNS takes the first response, this IP address will be written to its database and served to the users.  Consequently, if a user tries to go to a website they might be redirected to a malicious website instead.