Welcome MadHunteR, the newest member
New user?    Register    Login
http://www.attackprevention.com Check out our new Techie Humor category!


Date Submitted: 08/23/05
Hits: 32
Rating: 00000 based on 0 votes

Predictability of Windows DNS resolver


Added by Papergrl

Description: The main DNS security issues have very often focused on server side problems and vulnerabilities. This paper focuses on Windows client DNS service, also called DNS resolver. This paper explains how it is often possible to predict the "Transaction ID" and the "UDP port number" used by Windows' DNS Resolver. With this information it will be shown how it is possible, under certain conditions, to win the race against the regular DNS server and hijack, for example, a TCP/IP session. Even if this problem has been reported to Microsoft's security experts and we both agreed that there is no immediate threat or security vulnerability, it may be used to attack Windows LAN and WAN clients for example at startup. In WLAN too, which shares the medium and then is subjected to the well-known DNS attacks based on sniffing, this predictability increases the chances of being effectively attacked.

Read the Complete Paper



Post Comment
Guest Name:

Title


Comment You may use Posting Codes in your message.

Security Image:
Type the letters and numbers shown. (This is to prevent automated submissions.)
security

Copyright 2008 AttackPrevention