Black Hat Asia 2026 | Systematically Exploring and Exploiting DNS Silent Vulnerabilities

MediaVideo

Domain names function as human-readable identifiers on the Internet, with characters serving as their essential building blocks. However, since the initial specification of domain names in 1983, the security implications of handling special characters within the domain name resolution process have remained largely overlooked.

In this work, we conducted the first systematic study of special character handling logic in DNS, reviewing DNS RFCs and analyzing 31 widely-used DNS software implementations through source code review and gray-box testing. Our systematic analysis reveals two new DNS logic vulnerabilities arising from inconsistencies and silent handling behaviors, leading to two classes of attacks (four variants) that affect all DNS roles, including stub resolvers, forwarders, recursive resolvers, and authoritative nameservers. We name them the SHAR attack. Attackers can exploit these vulnerabilities to launch DNS cache poisoning and load balancing disruption attacks. Through comprehensive experiments, we validated the impact on the real world. All 31 tested mainstream DNS software implementations are vulnerable to SHAR. Notably, attackers can seize control of domain names, even the entire TLD or deceive victim resolvers to return invalid responses for legitimate queries, resulting in a persistent DoS effect. The SHAR attack can also enhance 10/13 well-known off-path DNS cache poisoning attacks (2002–2025).

To further determine the impact in the wild, we test all DNS-related roles, including mainstream Wi-Fi routers, router OSes, public DNS services, table open DNS resolvers, Root servers, TLD servers, SLD servers, and domain names. The results show that the SHAR attack affects all tested Wi-Fi routers, router OSes, and public DNS services. In addition, we identified that over 12.5M domain names are also vulnerable to the SHAR attack.

Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors.

Fasheng Miao | Master Student, Tsinghua University
Xiang Li | Associate Professor, Nankai University
Changqing An | Associate Researcher, Tsinghua University
Jilong Wang | Professor, Tsinghua University

https://blackhat.com/asia-26/briefings/schedule/?#one-char-to-rule-them-all-systematically-exploring-and-exploiting-dns-silent-vulnerabilities-in-domain-name-resolution-50554Black HatRead More