Xiang Li | 李想
Xiang Li | 李想
Home
Publications
Projects
Activities
Misc
Contact
Links
Light
Dark
Automatic
English
中文 (简体)
DNS Security
TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers
In this paper, we present the
TsuKing
attack.
Wei Xu
,
Xiang Li
,
Chaoyi Lu
,
Baojun Liu
,
Jia Zhang
,
Jianjun Chen
,
Tao Wan
,
Haixin Duan
PDF
Cite
Code
Project
TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers
In this paper, we present the
TsuKing
attack.
Wei Xu
,
Xiang Li
,
Chaoyi Lu
,
Baojun Liu
,
Jia Zhang
,
Jianjun Chen
,
Tao Wan
,
Haixin Duan
Nov 26, 2023
DNS
PDF
Cite
Code
Project
Wolf in Sheep's Clothing: Evaluating the Security Risks of the Undelegated Record on DNS Hosting Services
This paper conducted a comprehensive measurement to reveal the prevalence of undelegated DNS records.
Fenglu Zhang
,
Yunyi Zhang
,
Baojun Liu
,
Eihal Alowaisheq
,
Lingyun Ying
,
Xiang Li
,
Zaifeng Zhang
,
Ying Liu
,
Haixin Duan
,
Min Zhang
PDF
Cite
Code
Project
The Maginot Line: Attacking the Boundary of DNS Caching Protection
In this paper, we report
MaginotDNS
, a powerful cache poisoning attack against DNS servers that simultaneously act as recursive resolvers and forwarders (termed as
CDNS
).
Xiang Li
,
Chaoyi Lu
,
Baojun Liu
,
Qifan Zhang
,
Zhou Li
,
Haixin Duan
,
Qi Li
PDF
Cite
Code
Project
Slides
Source Document
The Maginot Line: Attacking the Boundary of DNS Caching Protection
在本文中,我们报告了
MaginotDNS
,这是针对同时充当递归解析器和转发器(称为
CDNS
)的DNS服务器的强大缓存投毒攻击。
Xiang Li
,
Chaoyi Lu
,
Baojun Liu
,
Qifan Zhang
,
Zhou Li
,
Haixin Duan
,
Qi Li
Aug 9, 2023
DNS
PDF
Cite
Code
Project
Slides
Source Document
DareShark: Detecting and Measuring Security Risks of Hosting-Based Dangling Domains
In this paper, we present a novel framework,
HostingChecker
(
DareShark
), for detecting domain takeovers.
Mingming Zhang
,
Xiang Li
,
Baojun Liu
,
Jianyu Lu
,
Jianjun Chen
,
Yiming Zhang
,
Xiaofeng Zheng
,
Haixin Duan
,
Shuang Hao
PDF
Cite
Slides
DareShark: Detecting and Measuring Security Risks of Hosting-Based Dangling Domains
In this paper, we present a novel framework,
HostingChecker
(
DareShark
), for detecting domain takeovers.
Mingming Zhang
,
Xiang Li
,
Baojun Liu
,
Jianyu Lu
,
Jianjun Chen
,
Yiming Zhang
,
Xiaofeng Zheng
,
Haixin Duan
,
Shuang Hao
Jun 19, 2023
DNS
PDF
Cite
Slides
Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
In this paper, we propose
Phoenix Domain
, a general and novel attack that allows adversaries to maintain the revoked malicious domain continuously resolvable at scale, which enables an old, mitigated attack, Ghost Domain.
Xiang Li
,
Baojun Liu
,
Xuesong Bai
,
Mingming Zhang
,
Qifan Zhang
,
Zhou Li
,
Haixin Duan
,
Qi Li
PDF
Cite
Code
Project
Slides
Source Document
DOI
Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
In this paper, we propose
Phoenix Domain
, a general and novel attack that allows adversaries to maintain the revoked malicious domain continuously resolvable at scale, which enables an old, mitigated attack, Ghost Domain.
Xiang Li
,
Baojun Liu
,
Xuesong Bai
,
Mingming Zhang
,
Qifan Zhang
,
Zhou Li
,
Haixin Duan
,
Qi Li
Feb 27, 2023
DNS
PDF
Cite
Code
Project
Slides
Source Document
DOI
«
Cite
×