<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.byte-welt.net/index.php?action=history&amp;feed=atom&amp;title=DNS-Cache-Poisoning</id>
	<title>DNS-Cache-Poisoning - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.byte-welt.net/index.php?action=history&amp;feed=atom&amp;title=DNS-Cache-Poisoning"/>
	<link rel="alternate" type="text/html" href="https://wiki.byte-welt.net/index.php?title=DNS-Cache-Poisoning&amp;action=history"/>
	<updated>2026-08-22T17:45:27Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Byte-Welt Wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.byte-welt.net/index.php?title=DNS-Cache-Poisoning&amp;diff=3892&amp;oldid=prev</id>
		<title>EagleEye: /* Links */</title>
		<link rel="alternate" type="text/html" href="https://wiki.byte-welt.net/index.php?title=DNS-Cache-Poisoning&amp;diff=3892&amp;oldid=prev"/>
		<updated>2009-01-12T20:34:00Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Links&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 12. Januar 2009, 20:34 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l21&quot;&gt;Zeile 21:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 21:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*[http://www.kb.cert.org/vuls/id/457875 US-CERT VU#457875 (Various DNS service implementations generate multiple simultaneous queries for the same resource record)]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*[http://www.kb.cert.org/vuls/id/457875 US-CERT VU#457875 (Various DNS service implementations generate multiple simultaneous queries for the same resource record)]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*[http://www.kb.cert.org/vuls/id/800113 US-CERT VU#800113 (Multiple DNS implementations vulnerable to cache poisoning)]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*[http://www.kb.cert.org/vuls/id/800113 US-CERT VU#800113 (Multiple DNS implementations vulnerable to cache poisoning)]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;*[http://ftp.ccc.de/congress/25c3/video_h264_720x576/25c3-2906-en-why_were_we_so_vulnerable_to_the_dns_vulnerability.mp4 25c3 Videobeitrag]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==News Artikel==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==News Artikel==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key bytewelt_wiki:diff:1.41:old-3431:rev-3892:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>EagleEye</name></author>
	</entry>
	<entry>
		<id>https://wiki.byte-welt.net/index.php?title=DNS-Cache-Poisoning&amp;diff=3431&amp;oldid=prev</id>
		<title>EagleEye: Die Seite wurde neu angelegt: DNS-Cache-Poisoning ist ein Angriff auf DNS-Server, dabei werden in den Cache des Servers falsche DNS-Einträge hinterlegt. Diese Informationen würden ansc...</title>
		<link rel="alternate" type="text/html" href="https://wiki.byte-welt.net/index.php?title=DNS-Cache-Poisoning&amp;diff=3431&amp;oldid=prev"/>
		<updated>2008-09-02T12:31:34Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: DNS-Cache-Poisoning ist ein Angriff auf &lt;a href=&quot;/index.php/DNS&quot; title=&quot;DNS&quot;&gt;DNS&lt;/a&gt;-&lt;a href=&quot;/index.php/Server&quot; title=&quot;Server&quot;&gt;Server&lt;/a&gt;, dabei werden in den &lt;a href=&quot;/index.php?title=Cache&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Cache (Seite nicht vorhanden)&quot;&gt;Cache&lt;/a&gt; des Servers falsche DNS-Einträge hinterlegt. Diese Informationen würden ansc...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;DNS-Cache-Poisoning ist ein Angriff auf [[DNS]]-[[Server]], dabei werden in den [[Cache]] des Servers falsche DNS-Einträge hinterlegt. Diese Informationen würden anschließend an die Clients (Benutzer) weitergegeben werden, wodurch diese auf falsche Seiten weiter geleitet werden.&lt;br /&gt;
&lt;br /&gt;
==Ursprung==&lt;br /&gt;
Für eine schnellere Abarbeitung der Anfragen von Clients setzen viele Server auf eine Cache. In diesem werden die Ergebnisse alter Abfragen zwischen gespeichert um so nicht jede Abfrage erneut ausführen zu müssen. Wird hier eine Adresse verändert wird diese ohne große Überprüfung an die Clients weitergegeben.&lt;br /&gt;
&lt;br /&gt;
==Methoden==&lt;br /&gt;
&amp;#039;&amp;#039;DNS Forgery&amp;#039;&amp;#039; beschreibt den Angriff auf einen Server, bei dem ihm erst eine rekursive Anfrage geschickt wird. Dabei ist das Ziel vor den anderen Server bzw. dem zuständigen Server, dem angegriffenen Server eine gefälschte Antwort zu schicken.&lt;br /&gt;
&lt;br /&gt;
==Gegenmaßnahmen==&lt;br /&gt;
Das DNS-Protokoll sieht für jede Anfrage eine Transaktions-ID vor, diese 16Bit Zahl wird zufällig gewählt. Um falsche Informationen zu hinterlegen muss diese ID erraten werden, im Durchschnitt benötigt man dafür 32768 Versuche. Die Wahl des [[UDP]] [[Port]]s ist auch für die Sicherheit wichtig, wird dieser zu selten gewechselt, kann er schnell angegriffen werden.&lt;br /&gt;
Ein Allheilmittel ist derzeit nicht verfügbar, für diesen Zweck müsste das gesamte DNS-Protokoll überarbeitet werden.&lt;br /&gt;
&lt;br /&gt;
==Exploids==&lt;br /&gt;
*[http://www.caughq.org/exploits/CAU-EX-2008-0002.txt CAU-EX-2008-0002 (Kaminsky DNS Cache Poisoning Flaw Exploit)]&lt;br /&gt;
*[http://www.caughq.org/exploits/CAU-EX-2008-0003.txt CAU-EX-2008-0003 (Kaminsky DNS Cache Poisoning Flaw Exploit for Domains)]&lt;br /&gt;
&lt;br /&gt;
==Links==&lt;br /&gt;
*[http://www.kb.cert.org/vuls/id/484649 US-CERT VU#484649 (Microsoft Windows DNS Server vulnerable to cache poisoning)]&lt;br /&gt;
*[http://www.kb.cert.org/vuls/id/252735 US-CERT VU#252735 (ISC BIND generates cryptographically weak DNS query IDs)]&lt;br /&gt;
*[http://www.kb.cert.org/vuls/id/927905 US-CERT VU#927905 (BIND version 8 generates cryptographically weak DNS query identifiers)]&lt;br /&gt;
*[http://www.kb.cert.org/vuls/id/457875 US-CERT VU#457875 (Various DNS service implementations generate multiple simultaneous queries for the same resource record)]&lt;br /&gt;
*[http://www.kb.cert.org/vuls/id/800113 US-CERT VU#800113 (Multiple DNS implementations vulnerable to cache poisoning)]&lt;br /&gt;
&lt;br /&gt;
==News Artikel==&lt;br /&gt;
*[http://www.golem.de/0807/60935.html Golem.de]&lt;br /&gt;
*[http://www.heise.de/security/Massives-DNS-Sicherheitsproblem-gefaehrdet-das-Internet--/news/meldung/110641 heise]&lt;br /&gt;
&lt;br /&gt;
[[Kategorie:Sicherheitslücken]]&lt;/div&gt;</summary>
		<author><name>EagleEye</name></author>
	</entry>
</feed>