Using the Domain Name System for System Break-ins
Steven M. Bellovin
Presented by: Thomas Repantis
trep@cs.ucr.edu
CS255-Computer Security, Winter 2004 – p.1/37
Using the Domain Name System for System Break-ins Steven M. - - PowerPoint PPT Presentation
Using the Domain Name System for System Break-ins Steven M. Bellovin Presented by: Thomas Repantis trep@cs.ucr.edu CS255-Computer Security, Winter 2004 p.1/37 Overview Using DNS to spoof a hosts name and access network services that
Presented by: Thomas Repantis
trep@cs.ucr.edu
CS255-Computer Security, Winter 2004 – p.1/37
CS255-Computer Security, Winter 2004 – p.2/37
CS255-Computer Security, Winter 2004 – p.3/37
CS255-Computer Security, Winter 2004 – p.4/37
CS255-Computer Security, Winter 2004 – p.5/37
CS255-Computer Security, Winter 2004 – p.6/37
CS255-Computer Security, Winter 2004 – p.7/37
CS255-Computer Security, Winter 2004 – p.8/37
CS255-Computer Security, Winter 2004 – p.9/37
CS255-Computer Security, Winter 2004 – p.10/37
CS255-Computer Security, Winter 2004 – p.11/37
CS255-Computer Security, Winter 2004 – p.12/37
CS255-Computer Security, Winter 2004 – p.13/37
CS255-Computer Security, Winter 2004 – p.14/37
CS255-Computer Security, Winter 2004 – p.15/37
CS255-Computer Security, Winter 2004 – p.16/37
CS255-Computer Security, Winter 2004 – p.17/37
CS255-Computer Security, Winter 2004 – p.18/37
CS255-Computer Security, Winter 2004 – p.19/37
CS255-Computer Security, Winter 2004 – p.20/37
CS255-Computer Security, Winter 2004 – p.21/37
CS255-Computer Security, Winter 2004 – p.22/37
CS255-Computer Security, Winter 2004 – p.23/37
CS255-Computer Security, Winter 2004 – p.24/37
CS255-Computer Security, Winter 2004 – p.25/37
CS255-Computer Security, Winter 2004 – p.26/37
CS255-Computer Security, Winter 2004 – p.27/37
CS255-Computer Security, Winter 2004 – p.28/37
CS255-Computer Security, Winter 2004 – p.29/37
CS255-Computer Security, Winter 2004 – p.30/37
CS255-Computer Security, Winter 2004 – p.31/37
CS255-Computer Security, Winter 2004 – p.32/37
CS255-Computer Security, Winter 2004 – p.33/37
CS255-Computer Security, Winter 2004 – p.34/37
CS255-Computer Security, Winter 2004 – p.35/37
. Mockapetris. RFC 1034: Domain Concepts and Facilities. IETF , 1987.
. Mockapetris. RFC 1035: Domain Implementation and Specifi cation. IETF , 1987.
1995.
. Vixie. DNS and BIND security issues. USENIX, 1995.
, 1999.
, 2003.
CS255-Computer Security, Winter 2004 – p.36/37
CS255-Computer Security, Winter 2004 – p.37/37