Budapesti Műszaki és Gazdaságtudományi Egyetem - BME -- Távközlési és Médiainformatikai Tanszék - TMIT Dept. of Telecommunications and Artificial Intelligence - TMIT
 
 
| IW  
 
 
Student topics

Támadások Elévült DNS Glue Rekordok Segítségével (Security Threats of Stale DNS Glue Records)

The Domain Name System (DNS) aids internet communication by translating human-readable domain names into machine-friendly IP addresses. The DNS fundamentally relies on glue records to provide the IP addresses of authoritative nameservers, enabling subdomain delegation. While previous studies have identified potential security risks associated with glue records, the exploitation of these records, particularly in the context of out-domain delegation, remains unclear. These records are inherently less reliable, and resolvers handle them in various ways. The recursive traversal of the delegation chain between parent and child authoritative nameservers ensures domain name resolution. Parent domains contain delegation records that point to the designated nameservers of their subdomains. However, a paradoxical loop emerges when attempting to resolve a subdomain delegated by its parent domain (e.g., ns.foo.com, delegated by foo.com). This recursion is resolved using glue records, which contain nameserver IP addresses stored within the delegating parent's zone file and are only used in referral responses. Tasks: Evaluate the real-world impact of stale records by conducting measurements on open DNS resolvers. Gather empirical data showing that the vast majority of DNS resolvers in operation are vulnerable to exploitation due to stale glue records.

The Domain Name System (DNS) aids internet communication by translating human-readable domain names into machine-friendly IP addresses. The DNS fundamentally relies on glue records to provide the IP addresses of authoritative nameservers, enabling subdomain delegation. While previous studies have identified potential security risks associated with glue records, the exploitation of these records, particularly in the context of out-domain delegation, remains unclear. These records are inherently less reliable, and resolvers handle them in various ways. The recursive traversal of the delegation chain between parent and child authoritative nameservers ensures domain name resolution. Parent domains contain delegation records that point to the designated nameservers of their subdomains. However, a paradoxical loop emerges when attempting to resolve a subdomain delegated by its parent domain (e.g., ns.foo.com, delegated by foo.com). This recursion is resolved using glue records, which contain nameserver IP addresses stored within the delegating parent's zone file and are only used in referral responses. Tasks: Evaluate the real-world impact of stale records by conducting measurements on open DNS resolvers. Gather empirical data showing that the vast majority of DNS resolvers in operation are vulnerable to exploitation due to stale glue records.

Kulcsszavak: dns, internet, glue record, hack
Témavezető: Ladóczki Bence
Oktatók: Ladóczki Bence, Tapolcai János.
A következő tantárgyakhoz javasolt:
 vitma387 (Önlab, IVIR szakirány)
 vitma415 (Szakdolgozat)
 vitma416 (Szakdolgozat)
 vitma417 (Szakdolgozat, IVIR szakirány)
 vitmal01 (Info, BSc, Önálló laboratórium)
 vitmm855 (Info, MSc, Önálló laboratórium 2, Hálózatok és szolgáltatások)
 vitmm861 (Info, MSc, Önálló laboratórium 2, Médiainformatika)
 vitmm905 (Diplomatervezés 1. (Info, Hálózatok és szolgáltatások szakirány))
 vitmm911 (Diplomatervezés 1. (Info, Médiainformatika szakirány))
 vitmml10 (Info, MSc, Önálló laboratórium 1)
 vitmml11 (Info, MSc, Önálló laboratórium 2)
 vitma345 (Vill., BSc. Önálló laboratórium)
 vitma414 (Szakdolgozat)
 vitmal03 (Vill.mérn. BSc Önálló laboratórium)
 vitmm807 (Vill., MSc, Önálló laboratórium 1, Infokommunikációs rendszerek)
 vitmm857 (Vill., MSc, Önálló laboratórium 2, Infokommunikációs rendszerek)
 vitmm907 (Diplomatervezés 1. (Vill. Infokommunikációs rendszerek szakirány))
 vitmml02 (Vill,MSc,Önlab.1, Okos város,Vez.nélküli rendsz. és alk.ok,Multimédia rendsz. és szolg.,Optikai távközlés (VITMML02))
 vitmml03 (Vill,MSc,Önlab.2, Okos város,Vez.nélküli rendsz. és alk.ok,Multimédia rendsz. és szolg.,Optikai távközlés (VITMML03))
QR:    (mi is az?)
 
 katt. a nagyításhoz
 
Kedvencekbe felvesz   Jelentkezés