Security News

Investigating the Navalny Poisoning
2020-12-23 12:44

"We see where troll feeding leads." Unfortunately not "Feeding" makes this troll change food source.

Microsoft issues guidance for DNS cache poisoning vulnerability
2020-12-08 13:58

Microsoft issued guidance on how to mitigate a DNS cache poisoning vulnerability reported by security researchers from the University of California and Tsinghua University. Successfully exploiting the vulnerability could allow attackers to use modified DNS records to redirect a target to a malicious website under their control as part of DNS spoofing attacks.

SAD DNS cache poisoning: A temporarily fix for Linux servers and desktops
2020-11-13 15:51

Jack Wallen walks you through the process of putting in place a temporary fix against SAD DNS for your Linux servers and desktops. There's a new DNS cache poisoning threat in town and it goes by the name of Side-channel AttackeD DNS. This new attack works like so: SAD DNS makes it possible for hackers to reroute traffic destined to a specific domain to a server under their control.

SAD DNS — New Flaws Re-Enable DNS Cache Poisoning Attacks
2020-11-12 23:12

A group of academics from the University of California and Tsinghua University has uncovered a series of critical security flaws that could lead to a revival of DNS cache poisoning attacks. The effectiveness of such attacks has taken a hit in part due to protocols such as DNSSEC that creates a secure domain name system by adding cryptographic signatures to existing DNS records and randomization-based defenses that allow the DNS resolver to use a different source port and transaction ID for every query.

DNS cache poisoning attacks return due to Linux weakness
2020-11-12 15:55

Researchers from Tsinghua University and the University of California have identified a new method that can be used to conduct DNS cache poisoning attacks. DNS cache poisoning attacks refer to polluting this very cache existing on intermediary servers.

New Cache Poisoning Attack Lets Attackers Target CDN Protected Sites
2019-10-23 08:34

A team of German cybersecurity researchers has discovered a new cache poisoning attack against web caching systems that could be used by an attacker to force a targeted website into delivering...

PGP Ecosystem Targeted in ‘Poisoning’ Attacks
2019-07-05 17:05

Two researchers are being singled out in what are called PGP poisoning or flood attacks that render the authentication tool unusable for victims.

OpenPGP experts targeted by long-feared ‘poisoning’ attack
2019-07-05 11:43

Somebody out there has taken a big dislike to Robert J. Hansen (‘rjh’) and Daniel Kahn Gillmor (‘dkg’), two well-regarded experts in the specialised world of OpenPGP email encryption.

StatCounter fingers cache-poisoning caper for Bitcoin-slurping JavaScript hijack
2018-11-08 04:52

The good news? Nobody appears to have lost any Bitcoin, says Gate.io This week's hijacking of StatCounter's JavaScript to swipe Bitcoins from a crypto-coin exchange was the result of a web cache...

Web cache poisoning just got real
2018-08-17 16:05

Cache me outside, how 'bout dah? BSides Manchester Websites can be compromised to turn their caches into exploit delivery systems.…