Detailedlikelihood: Highseverity: HighDraft

CAPEC-142DNS Cache Poisoning

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High

Description

A domain name server translates a domain name (such as www.example.com) into an IP address that Internet hosts use to contact Internet resources. An adversary modifies a public DNS cache to cause certain names to resolve to incorrect addresses that the adversary specifies. The result is that client applications that rely upon the targeted cache for domain name resolution will be directed not to the actual address of the specified domain name but to some other address. Adversaries can use this to herd clients to sites that install malware on the victim's computer or to masquerade as part of a Pharming attack.

Related weaknesses· 5

CWE-348CWE-345CWE-349CWE-346CWE-350

MITRE ATT&CK crosswalk· 1

T1584.002: Compromise Infrastructure: DNS Server

Related attack patterns· 2

CAPEC-141 (ChildOf)CAPEC-89 (CanPrecede)

Exploits5

TypeTargetConfidenceTier
WeaknessInsufficient Verification of Data Authenticitycwe-345100%live
WeaknessOrigin Validation Errorcwe-346100%live
WeaknessAcceptance of Extraneous Untrusted Data With Trusted Datacwe-349100%live
WeaknessUse of Less Trusted Sourcecwe-348100%live
WeaknessReliance on Reverse DNS Resolution for a Security-Critical Actioncwe-350100%live

Related to1

TypeTargetConfidenceTier
SubTechniqueDNS Servert1584.002100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Cache Poisoning
CAPEC
DNS Spoofing
CAPEC
DNS Rebinding
CAPEC
DNS Blocking
CAPEC
Poison Web Service Registry
CAPEC
Schema Poisoning
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.