"KeyTrap DNS Attack Disrupts Internet Access with Single Packet"

TL;DR Summary
A serious vulnerability named KeyTrap in the DNSSEC feature of the Domain Name System (DNS) could be exploited to cause long-lasting denial-of-service (DoS) conditions in vulnerable resolvers by sending a single DNS packet, potentially disrupting internet access for applications. The flaw, present for over two decades, was discovered by researchers and impacts widely used DNS implementations. Mitigations have been developed by companies like Akamai, Google, and Cloudflare to address the issue, but addressing the problem at a fundamental level may require a reevaluation of the DNSSEC design philosophy.
- KeyTrap attack: Internet access disrupted with one DNS packet BleepingComputer
- DNS Server Vulnerability: Single DNS Packet can Bring Down the System GBHackers
- Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC The Register
- KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers SecurityWeek
- DNS resolvers inherited specification bug - Security iTnews
Reading Insights
Total Reads
0
Unique Readers
0
Time Saved
3 min
vs 4 min read
Condensed
86%
633 → 88 words
Want the full story? Read the original article
Read on BleepingComputer