作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (4): 125-127. doi: 10.3969/j.issn.1000-3428.2009.04.044

• 安全技术 • 上一篇    下一篇

基于DNS缓存中毒的Webmail攻击及防护

张红轻,王道顺   

  1. (清华大学计算机科学与技术系,北京 100084)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-02-20 发布日期:2009-02-20

Attack and Defense of Webmail Based on DNS Cache Poisoning

ZHANG Hong-qing, WANG Dao-shun   

  1. (Department of Computer Science and Technology, Tsinghua University, Beijing 100084)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-02-20 Published:2009-02-20

摘要: 针对Webmail的特性,提出一种基于域名系统(DNS)缓存中毒(Cache Poisoning)的Web邮箱(Webmail)攻击技术,并对整个攻击流程进行描述,实现了对当前安全性较高的Live Mail的成功攻击,验证DNS Cache Poisoning潜在的危害性,提出相应的安全防护手段。

关键词: 域名系统, 缓存中毒, Web邮箱, 攻击

Abstract: According to the characteristics of Webmail, this paper proposes a new attack method based on DNS Cache Poisoning, and presents an attacking framework. Experimental results show that it can attack Live Mail successfully, so it can testify the potential risk of DNS Cache Poisoning. Three methods are given to defense the attack.

Key words: DNS, Cache Poisoning, Webmail, attack

中图分类号: