
11/13/2020 · Marek Vavruša, Nick Sullivan
What this post added
This post details the SAD DNS attack, which exploits UDP fragmentation and ICMP error messages to bypass source port randomization in DNS resolvers, enabling DNS cache poisoning. Cloudflare has mitigated this vulnerability by disabling fragmented DNS responses and enhancing its recursive resolver to reject malformed ICMP error messages. The post also provides background on DNS basics, the DNS ecosystem, and previous attacks like Kaminsky's attack, highlighting the ongoing challenges in securing DNS communications over UDP.