Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets

Black Hat via YouTube

Overview

Coursera Plus Monthly Sale: All Certificates & Courses 40% Off!
Explore a 26-minute Black Hat conference talk that delves into the systematic exploration and exploitation of logic vulnerabilities in DNS response pre-processing. Learn about the TuDoor attack, which reveals three new types of logic vulnerabilities in DNS implementations. The presenters demonstrate how malformed DNS response packets can be used for DNS cache poisoning (completing in less than 1 second), denial-of-service, and resource consumption attacks. The research shows that 24 mainstream DNS software implementations, including BIND, PowerDNS, and Microsoft DNS, are vulnerable to these attacks. The speakers share their findings from testing 16 Wi-Fi routers, 6 router operating systems, 42 public DNS services, and approximately 1.8 million open DNS resolvers, revealing that TuDoor could exploit 7 routers/OSes, 18 public DNS services, and 424,652 open DNS resolvers. The talk covers the responsible disclosure process, resulting in 33 CVE IDs and acknowledgments from major vendors like BIND, Chrome, Cloudflare, and Microsoft. Visit tudoor.net for comprehensive details and the full CVE list. Presented by Qi Wang (PhD Student, Tsinghua University), Xiang Li (Associate Professor, Nankai University), and Chuhan Wang (PhD Candidate, Tsinghua University).

Syllabus

TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities

Taught by

Black Hat

Reviews

Start your review of TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.