Unveiling Localhost Table Poisoning: Data At Risk?
By Tom Seest
Is Your Data At Risk? Uncovering Localhost Table Poisoning
At BestCybersecurityNews, we help entrepreneurs, solopreneurs, young learners, and seniors learn more about cybersecurity.
Analysis of host data on %Compromised Host revealed several domain accounts being queried rapidly by various domain services – indicative of potential phishing document attacks that are indicative of compromise.
Poisoning attacks can be countered through robust learning and using additional tools, as the authors demonstrate in various learning tasks.

Is Your Data At Risk? Uncovering Localhost Table Poisoning
Table Of Contents
Can Your Localhost Table Be Poisoned? Uncovering the Dangers of Table Poisoning
This attack takes advantage of a DNS flaw to exploit and inject fake responses into DNS queries. An attacker must first wait for a query from one recursive name server before rapidly flooding it with thousands of forged requests with different transaction IDs in order to poison its cache.
Such attacks can be devastating. For instance, in a recent attack against Boleto transactions, malware would inject DNS records in victims’ local cache that point mail and web domains back to infrastructure controlled by an attacker – giving access to usernames and passwords collected while users used Boleto Bank website.
This attack works because most people are unaware that both Microsoft Windows workstations and Apple OS X workstations come equipped with default configurations that create a local DNS cache, using responses from configured recursive servers, to speed up visiting frequently visited domains; however, this opens the door for attacks. By running the command ipconfig /displaydns you can see what information is in your DNS cache.

Can Your Localhost Table Be Poisoned? Uncovering the Dangers of Table Poisoning
Are You Prepared to Defend Against Localhost Table Poisoning?
At its heart lies this type of attack: malware exploiting undocumented DNS API calls that allow it to add records directly into a victim workstation’s local cache. Once poisoning has taken place, an attacker could flood a recursive server with fake responses containing transaction IDs that point back at their server containing fake transactions from banks controlled by them, all containing transaction IDs that point victims’ banks back toward an attacker-controlled server containing transaction IDs controlled by themselves. DNSSEC protection may offer protection; however this protection is currently limited; researchers discovered an attack against Boleto transactions using this technique in one case study.

Are You Prepared to Defend Against Localhost Table Poisoning?
Please share this post with your friends, family, or business associates who may encounter cybersecurity attacks.











