DNS this week stands for Drowning Needed Services: Design flaw in name server system can be exploited to flood machines offline

CERT-LatestNews DDoS-Threats ThreatsCybercrime Uncategorized VulnerabilitiesAll VulnerabilitiesApplications VulnerabilitiesDBMS VulnerabilitiesGoogle VulnerabilitiesMicrosoft VulnerabilitiesNetwork VulnerabilitiesOracle

The attacker uses the authoritative that it owns to craft a response to a resolver with a referral that contains n new and nonexistent name-server names without an associated IP address, and as a result, this resolver starts the process of F new resolutions.