RSSAmplifier

Blog

Xiang Li | 李想

Xiang Li | 李想

lixiang521.comRSS feed ↗93 posts

Latest posts

RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox

Overview RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. CVE/CNNVD (50/2) 2025: 13/2 2024: 37/0 BIND : CVE-2025-40776 (High) CNNVD-202507-2228 (High) PowerDNS : CVE-2025-30192 (High) CNNVD-202507-2635 (High) Unbound : CVE-2025-5994 (High) D-Link: CVE-2025-46663 CVE-2025-46665…

RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox

Overview RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. CVE/CNNVD (50/2) 2025: 13/2 2024: 37/0 BIND : CVE-2025-40776 (高危) CNNVD-202507-2228 (高危) PowerDNS : CVE-2025-30192 (高危) CNNVD-202507-2635 (高危) Unbound : CVE-2025-5994 (高危) D-Link: CVE-2025-46663 CVE-2025-46665 CVE-2025-46668…

ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing

Overview In this paper, we propose ResolverFuzz to fuzz the resolver. CVE/CNNVD (15/8) BIND : CVE-2021-25220 (Medium) CNNVD-202203-1514 (Medium) Technitium : CVE-2021-43105 (Medium) CNNVD-202203-2379 (Medium) Knot Resolver : CVE-2022-32983 (Medium) CNNVD-202206-2074 (Medium) Knot Resolver : CVE-2022-30250 PowerDNS Recursor : CVE-2022-30252 MaraDNS : CVE-2022-30256 (High) CNNVD-202211-3148 (High)…

ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing

概述 在本文中,我们提出了一个全新的工具 ResolverFuzz 用来模糊测试解析器。 CVE/CNNVD (15/8) BIND : CVE-2021-25220 (中危) CNNVD-202203-1514 (中危) Technitium : CVE-2021-43105 (中危) CNNVD-202203-2379 (中危) Knot Resolver : CVE-2022-32983 (中危) CNNVD-202206-2074 (中危) Knot Resolver : CVE-2022-30250 PowerDNS Recursor : CVE-2022-30252 MaraDNS : CVE-2022-30256 (高危) CNNVD-202211-3148 (高危) Technitium : CVE-2022-30257 (超危) CNNVD-202211-3247…

Rethinking the Security Threats of Stale DNS Glue Records

Overview In this paper, we rethink the security threats of stale DNS glue records. Presentation Presented in XCon 2024

Rethinking the Security Threats of Stale DNS Glue Records

Overview 在本文中,我们深入分析了DNS glue records的安全性。 展示 分享于 XCon 2024

Black Hat USA 2024

In Black Hat USA 2024, Qi Wang presented my work: “TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets”.

黑帽大会2024(美国)

在黑帽大会2024(美国)上, 汪琦学弟分享了我的研究工作:“TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets”。

GeekCon International 2024

In GeekCon International 2024 , Prof. Duan and me presented the TuDoor attack and showed a live demo. We got the Extraordinary Hacker honor. Moments

新极棒国际站 2024

在 新极棒国际站 2024 ,段老师和我演示了TuDoor攻击并获得了非凡黑客荣誉称号。 比赛时刻

45th IEEE Symposium on Security and Privacy 2024 | IEEE S&P 2024

In 45th IEEE Symposium on Security and Privacy 2024 , Fenglu presented our novel DNSBomb attack on behalf of me cause I couldn’t make it there. Feedback from the site impressive! unbelievable! amazing!

45th IEEE Symposium on Security and Privacy 2024 | IEEE S&P 2024

在 45th IEEE Symposium on Security and Privacy 2024 会议上,丰露代替我汇报了DNSBomb攻击。十分感谢! 现场反馈 impressive! unbelievable! amazing!

45th IEEE Symposium on Security and Privacy 2024 | IEEE S&P 2024

在 45th IEEE Symposium on Security and Privacy 2024 会议上,丰露代替我汇报了TuDoor攻击。十分感谢! 现场反馈 impressive! unbelievable! amazing!

DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses

Overview DNSBomb is a new practical and powerful pulsing DoS attack exploiting DNS queries and responses. We concluded that ANY SYSTEM or MECHANISM , which can aggregate “things”, could be exploited to construct the pulsing DoS traffic, such as DNS and CDN. Please join us to find more if you can! It is very interesting. DNSBomb: https://dnsbomb.net/ CVE/CNNVD (11/4) 2024: 1/3 2023:…

DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses

概述 DNSBomb is a new practical and powerful pulsing DoS attack exploiting DNS queries and responses. We concluded that ANY SYSTEM or MECHANISM , which can aggregate “things”, could be exploited to construct the pulsing DoS traffic, such as DNS and CDN. Please join us to find more if you can! It is very interesting. DNS炸弹: https://dnsbomb.net/ CVE/CNNVD (11/4) 2024: 1/3 2023: 10/1…

TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets

Overview This paper proposes the TuDoor Attack, by systematically exploring and exploiting logic vulnerabilities in DNS response pre-processing with malformed packets, leading to DNS cache poisoning (1s), denial-of-service, and resource consuming attacks. TuDoor: https://tudoor.net/ CVE/CNNVD (34/10) Microsoft : CVE-2023-32020 (Medium) CNNVD-202306-1013 (Medium) Knot : CVE-2023-26249 (High)…

TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets

概述 本论文提出了“突门攻击”,通过系统地探索并利用畸形数据包中DNS响应预处理的逻辑漏洞,导致DNS缓存投毒(1秒)、拒绝服务和资源消耗攻击。 突门攻击: https://tudoor.net/ CVE/CNNVD (34/10) Microsoft : CVE-2023-32020 (中危) CNNVD-202306-1013 (中危) Knot : CVE-2023-26249 (高危) CNNVD-202302-1645 (高危) PowerDNS : CVE-2023-26437 (中危) CNNVD-202304-131 (中危) Technitium : CVE-2023-28451 (中危) CNNVD-202409-1745 (中危) Simple DNS Plus : CVE-2023-28453 CoreDNS : CVE-2023-28452 (中危)…

BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet

Overview This paper proposes a BreakSPF attack framework, a newly discovered method for attackers to bypass the SPF protocol and launch email spoofing attacks.

BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet

概述 本论文提出了一个名为BreakSPF的攻击框架:攻击者新发现的一种绕过SPF协议并发起电子邮件欺骗攻击的方法。

Poster: ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing

概述 在本文中,我们提出了一个全新的工具 ResolverFuzz 用来模糊测试解析器。 漏洞编号 (15) BIND : CVE-2021-25220 Technitium : CVE-2021-43105 Knot Resolver : CVE-2022-32983 Knot Resolver : CVE-2022-30250 PowerDNS Recursor : CVE-2022-30252 MaraDNS : CVE-2022-30256 Technitium : CVE-2022-30257 Unbound : CVE-2022-30698 Technitium : CVE-2022-48256 MaraDNS : CVE-2023-22905 PowerDNS Recursor : CVE-2023-24712 Knot : CVE-2023-26249 Knot :…

Poster: ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing

Overview In this paper, we propose ResolverFuzz to fuzz the resolver. CVE (15) BIND : CVE-2021-25220 Technitium : CVE-2021-43105 Knot Resolver : CVE-2022-32983 Knot Resolver : CVE-2022-30250 PowerDNS Recursor : CVE-2022-30252 MaraDNS : CVE-2022-30256 Technitium : CVE-2022-30257 Unbound : CVE-2022-30698 Technitium : CVE-2022-48256 MaraDNS : CVE-2023-22905 PowerDNS Recursor : CVE-2023-24712 Knot :…

ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies with Differential Fuzzing

Overview This paper proposes a new automated fuzzing tool “ReqsMiner” to discover CDN forwarding request inconsistencies. More details coming soon…

ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies with Differential Fuzzing

概述 该文提出一种新的自动化模糊测试工具“ReqsMiner”来发现CDN转发请求的不一致。

Understanding the Implementation and Security Implications of Protective DNS Services

Overview This paper analyzes the ecosystem of protective DNS and its security issues. More details coming soon…

Understanding the Implementation and Security Implications of Protective DNS Services

概述 本文分析了Protective DNS的生态系统及其安全问题。

Black Hat Europe 2023

In Black Hat Europe 2023, Professor Haixin Duan presented our work: “TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers”.

黑帽大会2023(欧洲)

在黑帽大会2023(欧洲)上, 段海新教授分享了我们的研究工作:“TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers”。

TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers

Overview In this paper, we present the TsuKing attack. More details coming soon. TsuKing: https://tsuking.net/ CVE/CNNVD (3/1) Mikrotik : CVE-2023-24711 PowerDNS : CVE-2023-24712 Technitium : CVE-2023-28455 (High) CNNVD-202409-1743 (High) Presentation Presented in OARC 41 Presented in Black Hat Europe 2023

TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers

Overview In this paper, we present the TsuKing attack. More details coming soon. TsuKing: https://tsuking.net/ CVE/CNNVD (3/1) Mikrotik : CVE-2023-24711 PowerDNS : CVE-2023-24712 Technitium : CVE-2023-28455 (高危) CNNVD-202409-1743 (高危) Presentation Presented in OARC 41 Presented in Black Hat Europe 2023

Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild

Overview In this paper, we present a stealthy mining pool detection system. More details coming soon.

Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild

Overview In this paper, we present a stealthy mining pool detection system. More details coming soon.

GeekCon 2023

In GeekCon 2023 , I presented our 0-day vulnerability to conduct pulsing DoS attack with Dashuai. We got the 2nd prize of GeekCon 2023 DAF (Defense & Attack Force) Contest. Our colleagues got two Winner prizes and the 1st prize of AVSS contest. Moments

新极棒 2023

在 新极棒 2023 比赛中,我演示我们在DNS安全方面的最新研究成果:利用某种未知缺陷实现对任意网站的拒绝服务攻击(大四学弟吴大帅共同参赛,组建TNB团队),最后取得了GEEKCON 2023安全极客大赛“漏洞与利用DAF挑战赛”的亚军。我们实验室的其它参赛队伍获得了两项“漏洞与利用DAF挑战赛”的优胜奖和AVSS赛道的冠军。 比赛时刻

Wolf in Sheep's Clothing: Evaluating the Security Risks of the Undelegated Record on DNS Hosting Services

Overview This paper conducted a comprehensive measurement to reveal the prevalence of undelegated DNS records.

Wolf in Sheep's Clothing: Evaluating the Security Risks of the Undelegated Record on DNS Hosting Services

概述 本文对未授权的DNS记录的普遍性进行了全面的测量。

Kanxue SDC 2023

In Kanxue SDC 2023, Professor Haixin Duan presented our work: “The Maginot Line: Attacking the Boundary of DNS Caching Protection”.

看雪开发者峰会 2023

在看雪开发者峰会 2023,段海新教授分享了我们的工作:MaginotDNS 攻击——跨越域名解析器的缓存防御“护城河”。

Invited to Attend the 21st BlueHat 2023

On Augest 18, I was invited to attend the 21st BlueHat 2023. Event Details and FAQ: · Simply Applying does not ensure a pass or ticket to the conference: Click the ‘Apply Here!’ link above and complete the application form. If selected after our review, you will receive an email invitation with a unique link to register for the conference. · Microsoft employees will be assigned to Day 1 or Day 2…

受邀参加第21届BlueHat 2023

在8月18日,受邀参加第21届BlueHat 2023。 详情: · Simply Applying does not ensure a pass or ticket to the conference: Click the ‘Apply Here!’ link above and complete the application form. If selected after our review, you will receive an email invitation with a unique link to register for the conference. · Microsoft employees will be assigned to Day 1 or Day 2 of the event. While the agenda is still forthcoming,…

SHUZIHUANYU Dajia Talk 2023

In SHUZIHUANYU Dajia Talk 2023 (online class), I presented my MaginotDNS attack.

数字寰宇大家讲堂 2023

在 数字寰宇大家讲堂 2023 (在线),我分享了MaginotDNS攻击。

OARC 41 & ICANN DNS Symposium 2023

In OARC 41 & ICANN DNS Symposium 2023 (hybrid in-person and online workshop), Fenglu presented our novel TsuKing attack on behalf of me cause I couldn’t make it there. Feedback from workshops

OARC 41 & ICANN DNS Symposium 2023

在 OARC 41 & ICANN DNS Symposium 2023 会议上(线上线上相结合),丰露代替我演示了TsuKing攻击。十分感谢! 现场反馈

2nd AEGIS Workshop

In the 2nd AEGIS Workshop (online workshop), I presented a novel Ghost Domain attack named Phoenix Domain to the audiences.

2nd AEGIS Workshop

在第二届 AEGIS Workshop 中(线上),我分享了最新的研究工作 不死域名 。

Invited to MSRC's Researcher Celebration at Black Hat USA 2023

On July 11, I was invited to MSRC’s Researcher Celebration at Black Hat USA 2023. Event Details and FAQ: · When : Thursday, August 10th, 2023, from 5PM to 10PM · Where : Retro by Voltaggio, Mandalay Bay, Las Vegas · Who is the event for : MSRC’s Most Valuable Researchers (MVRs) and alumni, researchers with active and recent MSRC cases, MSRC strategic partners, and members of the security…

受邀参加 MSRC's Researcher Celebration at Black Hat USA 2023

在2023年7月11日,受邀参加 MSRC’s Researcher Celebration at Black Hat USA 2022。 详情: · When : Thursday, August 10th, 2023, from 5PM to 10PM · Where : Retro by Voltaggio, Mandalay Bay, Las Vegas · Who is the event for : MSRC’s Most Valuable Researchers (MVRs) and alumni, researchers with active and recent MSRC cases, MSRC strategic partners, and members of the security research community. · Can I have a…

2023年第32届USENIX安全探讨会|USENIX Security 2023

在2023年第32届USENIX安全探讨会上,我分享了最新研究工作:“The Maginot Line: Attacking the Boundary of DNS Caching Protection”,也见到和交到了很多朋友。

32nd USENIX Security Symposium 2023 | USENIX Security 2023

In the 2023 32nd USENIX Security Symposium, I presented one paper “The Maginot Line: Attacking the Boundary of DNS Caching Protection” to the audiences. I met many old friends and made many new friends.

Black Hat USA 2023

In Black Hat USA 2023, Professor Zhou Li presented our work: “The Maginot Line: Attacking the Boundary of DNS Caching Protection”.