DNS Poisoning
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If upstream DNS caches have been poisoned, attackers may be intercepting traffic before it even gets to you.
- Prevalence
- Rare
- Exploitability
- Difficult
- Impact
- Devastating
What is DNS poisoning?
DNS poisoning, also called DNS cache poisoning, is a spoofing attack in which an attacker inserts false records into a DNS resolver's cache. Users who look up your domain are given an IP address the attacker controls, allowing the attacker to intercept, read and manipulate traffic, or to serve a fake copy of your site.
What you'll learn
- How a domain lookup travels from resolver to root server to name server
- Where DNS caching gives attackers the chance to insert false records
- How HTTPS and DNSSEC protect users from poisoned lookups
This lesson includes
-
DNS Poisoning lab
Follow a domain lookup from the resolver to the root servers and down to the site's own name server, then see where caching creates openings for attackers. The lab covers edits to a victim's hosts file and the 2019 Sea Turtle campaign against a national top-level domain.
-
How to prevent DNS Poisoning
The prevention guide covers two approaches:
- Implement HTTPS
- Enable DNSSEC
-
DNS Poisoning quiz
Two questions. Passing marks the lesson complete.
Sources
- DNS Security Extensions (DNSSEC) Overview Google
- Configuring DNSSEC for an Amazon Web Services Domain AWS
- What is DNS Poisoning Cloudflare
- How DNSSEC works Cloudflare
Related lessons
Browse all 45 lessons
Subdomain Squatting
Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.
SSL Stripping
If only some actions on your website require HTTPS, an attacker may be able to steal credentials for your users.
Unencrypted Communication
Insufficient encryption can make you vulnerable to monster-in-the-middle attacks.
Email Spoofing
Email spoofing is the sending of email messages with a forged "from" address.