Slideshow: How DNS cache poisoning works

Tips to thwart DNS cache-poisoning attacks

Expiration of domain entry opens door: With cache poisoning an attacker tries to insert a fake address entry into a DNS server. In the past an attacker could only attack a DNS server when it was refreshing a cache entry.

1. Attacker figures out when a domain entry will expire on a caching server using readily available tools. 2. Attacker "races" the legitimate DNS server, trying to get the caching server to accept a fake response. 3. In order to be accepted the fake response must match query parameters of the actual response.

1 of 8
VIEW ALL THUMBNAILS

Best Deals on PCWorld

NotebooksView all »
TabletsView all »
Mobile PhonesView all »
Printers & ScannersView all »
Networking, Wireless & VoIPView all »

rhs_login_lockSign up to PC World Today for the latest news, reviews and galleries from PC World Australia.