How Attackers Use It
Attack Summary
Attacker injects forged DNS responses into a resolver's cache, redirecting a domain to a malicious IP before the legitimate TTL expires.
- Attacker predicts or races resolver query IDs and source ports.
- Forged answer is accepted and cached with malicious mapping.
- Users are redirected to phishing or malware-hosting domains.
- Credentials and sessions are harvested at scale.