Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
A$enda
DNS is distributed
Great for %i$% a,ai+abi+ity 5ac% ser,er is responsib+e on+y for its 6one
I.portant %eaders
Source IP, Source 7DP Port Destination IP, Destination 7DP Port DNS ID 0Identification1
7DP data$ra.s
3%e $odA-in$ %as betrayed a fata+ f+a*( ubris! 5asy to taunt, easy to tric-!
7DP can be easi+y spoofed
Any ISPs doin$ e$ress fi+terin$/ 3%ou$%t not!
Set SourceIP to t%at of t%e tar$et Set DestinationIP of 0a1 DNS ser,er Set DestinationPort to @; &ire a reIuest J for$et
Abuse DNSS5C
Good for a.p+ification due to +ar$e records for DNSP5Q or 88SIG resource records
Poor .anKs &i+e 3ransfer ,ia DNS by So%annes # Internet Stor. Center(
%ttp())isc!sans!edu)diary!%t.+/storyidG9:;:D
&eederbot botnet
7ses DNS 3O3 resource records for data transfer
8ep+y pay+oad $ets 8C< encrypted A C8C;> %eader is added 3%e *%o+e pac-a$e is no* BaseD< encoded 3%is for.s t%e DNS 3O3 response