DNS Posioning and Spoofing Made Simpler with BIND Vulnerability
Web page spoofing just got easier: One of the defenses against Domain Name System (DNS) cache poisoning and web address spoofing lies in the randomization of the IP address of the queried name server. But a newly found vulnerability in BIND, the most widely used DNS software on the internet, enables an attacker to de-randomize the queries—greatly reducing the time and effort required to successfully poison BIND's cache.