Title: A Security Problem and Proposed Correction With Widely Deployed DNS Software
Author(s): E. Gavron.
Status: INFORMATIONAL
Date: Oct 1993
Length: 9722
This document discusses a flaw in some of the currently distributed name resolver clients. The flaw exposes a security weakness related to the search heuristic invoked by these same resolvers when users provide a partial domain name, and which is easy to exploit (although not by the masses). This document points out the flaw, a case in point, and a solution.
|
|
|