Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-598 — DNS Spoofing
CAPEC-598

DNS Spoofing

TLP:CLEAR

Description

An adversary sends a malicious ("NXDOMAIN" ("No such domain") code, or DNS A record) response to a target's route request before a legitimate resolver can. This technique requires an On-path or In-path device that can monitor and respond to the target's DNS requests. This attack differs from BGP Tampering in that it directly responds to requests made by the target instead of polluting the routing the target's infrastructure uses.

Mitigation

Design: Avoid dependence on DNS | Design: Include "hosts file"/IP address in the application | Implementation: Utilize a .onion domain with Tor support | Implementation: DNSSEC | Implementation: DNS-hold-open

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.