DNS Security & Abuse
Threats, vulnerabilities, DNSSEC, and attack patterns.
8 articles · ~57 min total · reads in order
Why Attackers Use DNS
An architectural explanation of why DNS is frequently abused, rooted in how the protocol is designed and operated.
DNS Tunneling: How DNS Can Carry Data
How DNS tunneling repurposes ordinary queries and responses to carry data, how resolvers and caching shape the channel, and what defenders can observe.
Domain Generation Algorithms: How Malware Uses DNS to Find Infrastructure
How domain generation algorithms let malware and its infrastructure derive the same changing domain names, and what failed lookups reveal in DNS telemetry.
Fast Flux DNS: How Rapid Address Changes Obscure Infrastructure
How fast flux uses rapidly changing DNS answers and short TTLs to hide infrastructure, and why telling it apart from legitimate DNS takes time-series evidence.
DNS Cache Poisoning: How Forged Answers Enter Resolver Caches
How DNS cache poisoning works, why forged responses must match outstanding resolver transactions, and how modern DNS defenses reduce the risk.
DNSSEC: How DNS Answers Gain Cryptographic Authentication
How DNSSEC signs DNS data, builds a chain of trust through the DNS hierarchy, validates negative answers, and defines the limits of that authentication.
Dangling DNS Records: How Subdomain Takeover Becomes Possible
How stale DNS references to deleted third-party resources can create subdomain takeover risk, and why exploitability depends on provider ownership rules.
DNS Rebinding: How DNS Can Cross Browser Trust Boundaries
How DNS rebinding changes the address behind a stable hostname, why that interacts with browser same-origin rules, and which controls limit the attack.