The Impact of Dans DNS Debacle on Internet Risk
...impact on risk
First, it is worth noting that this bug is more properly classified as a new attack technique invented by Dan. It combines two vulnerabilities that have been well-known for some time the ability to guess non-random transaction IDs and the use of Additional RRs to insert new entries into the DNS cache. A fix against either of...
