<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>admin, Author at AIORI</title>
	<atom:link href="https://portal.aiori.in/author/admin/feed/" rel="self" type="application/rss+xml" />
	<link>https://portal.aiori.in</link>
	<description>Advanced Internet Operations Research in India</description>
	<lastBuildDate>Sun, 28 Jul 2024 13:59:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://portal.aiori.in/wp-content/uploads/2024/07/aio-150x150.png</url>
	<title>admin, Author at AIORI</title>
	<link>https://portal.aiori.in</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>DNS Key Trap</title>
		<link>https://portal.aiori.in/dns-key-trap/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 01 Apr 2024 13:36:56 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<guid isPermaLink="false">https://portal.aiori.in/?p=2041</guid>

					<description><![CDATA[<p>The DNS Key Trap According to the  National Vulnerability Database Certain aspects of DNSSEC in the DNS protocol, outlined in RFCs 4033, 4034, 4035, 6840, and related documents, enable remote attackers to initiate a denial of service (CPU consumption) through multiple DNSSEC responses, known as the &#8220;KeyTrap&#8221; issue. One significant concern is that when a [&#8230;]</p>
<p>The post <a href="https://portal.aiori.in/dns-key-trap/">DNS Key Trap</a> appeared first on <a href="https://portal.aiori.in">AIORI</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>The DNS Key Trap</h1>
<p>According to the  <a id="nvd-header-link" href="https://nvd.nist.gov/vuln/detail/CVE-2023-50387">National Vulnerability Database</a></p>
<blockquote>
<div class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">Certain aspects of DNSSEC in the DNS protocol, outlined in RFCs 4033, 4034, 4035, 6840, and related documents, enable remote attackers to initiate a denial of service (CPU consumption) through multiple DNSSEC responses, known as the &#8220;KeyTrap&#8221; issue. One significant concern is that when a zone contains numerous DNSKEY and RRSIG records, the protocol specification necessitates evaluating all possible combinations of these records.</div>
<div></div>
</blockquote>
<h3 class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8">Discovery</h3>
<blockquote><p>13.02.2024. The National Research Center for Applied Cybersecurity ATHENE has uncovered a critical flaw in the design of DNSSEC, the Security Extensions of DNS (Domain Name System). DNS is one of the fundamental building blocks of the Internet. The design flaw has devastating consequences for essentially all DNSSEC-validating DNS implementations and public DNS providers, such as Google and Cloudflare. The ATHENE team, led by Prof. Dr. Haya Schulmann from Goethe University Frankfurt, developed “KeyTrap”, a new class of attacks: with just a single DNS packet hackers could stall all widely used DNS implementations and public DNS providers. Exploitation of this attack would have severe consequences for any application using the Internet including unavailability of technologies such as web-browsing, e-mail, and instant messaging.</p></blockquote>
<p><strong>References:</strong></p>
<p><a href="https://www.athene-center.de/en/news/press/key-trap" target="_blank" rel="noopener">https://www.athene-center.de/en/news/press/key-trap</a></p>
<p><a href="https://www.athene-center.de/fileadmin/content/PDF/Keytrap_2401.pdf" target="_blank" rel="noopener">https://www.athene-center.de/fileadmin/content/PDF/Keytrap_2401.pdf</a></p>
<p>&nbsp;</p>
<blockquote><p>&nbsp;</p></blockquote>
<p>The post <a href="https://portal.aiori.in/dns-key-trap/">DNS Key Trap</a> appeared first on <a href="https://portal.aiori.in">AIORI</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
