Web Hack List

Preliminary research

DNS Cache Poisoning Like it's 2006

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Cache poisoning against BIND 9 that predicts BOTH values a spoofed answer must match - the UDP source port and the TXID - where most prior attacks predict only one, and does it entirely from the client side, with no attacker-operated authoritative server. The predictions come from weaknesses in BIND's pseudo-random number generation.

Record

Researcher
Omer Ben-Simhon and Amit Klein

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Omer Ben-Simhon and Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host.