{"id":39197,"date":"2021-01-19T14:26:56","date_gmt":"2021-01-19T14:26:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31943\/DNSpooq-Lets-Attackers-Poison-DNS-Cache-Records.html"},"modified":"2021-01-19T14:26:56","modified_gmt":"2021-01-19T14:26:56","slug":"dnspooq-lets-attackers-poison-dns-cache-records","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/","title":{"rendered":"DNSpooq Lets Attackers Poison DNS Cache Records"},"content":{"rendered":"<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2021\/01\/19\/33839159-0700-4e36-8dc2-0ee4a87bb165\/dnsspooq-logo.png\" class alt=\"dnsspooq-logo.png\"><\/span><figcaption><span class=\"caption\"><\/span><span class=\"credit\"> Image: JSOF <\/span><\/figcaption><\/figure>\n<p>Security experts have disclosed today details about seven vulnerabilities impacting a popular DNS software package that is commonly deployed in networking equipment, such as routers and access points.<\/p>\n<p>The vulnerabilities tracked as&nbsp;<strong>DNSpooq<\/strong>, impact&nbsp;<a href=\"http:\/\/www.thekelleys.org.uk\/dnsmasq\/doc.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Dnsmasq<\/a>, a DNS forwarding client for *NIX-based operating systems.<\/p>\n<p>Dnsmasq is usually included inside the firmware of various networking devices to provide DNS forwarding capabilities by taking DNS requests made by local users, forwarding the request to an upstream DNS server, and then caching the results once they arrive, making the same results readily available for other clients without needing to make a new DNS query upstream.<\/p>\n<p>While their role seems banal and insignificant, they play a crucial role in accelerating internet speeds by avoiding recursive traffic.<\/p>\n<p>Today, the DNSpooq software has made its way in millions of devices sold worldwide, such as Cisco devices, Android smartphones, and all sorts of networking gear like routers, access points, firewalls, and VPNs from companies like ZTE, Aruba, Redhat, Belden, Ubiquiti, D-Link, Huawei, Linksys, Zyxel, Juniper, Netgear, HPE, IBM, Siemens, Xiaomi, and others.<\/p>\n<h3>How DNSpooq works<\/h3>\n<p>The DNSpooq vulnerabilities, disclosed today by security experts from JSOF, are dangerous because they can be combined to poison DNS cache entries recorded by Dnsmasq servers.<\/p>\n<p>Poisoning DNS cache records is a big problem for network administrators because it allows attackers to redirect users to clones of legitimate websites.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>For example, if a threat actor can abuse a DNSpooq attack to poison DNS cache entries for gmail.com on a company&#8217;s Cisco router, they can redirect all that company&#8217;s employees to a Gmail phishing page while the browser shows the legitimate gmail.com address in their browsers.<\/p>\n<p>In total, seven DNSpooq vulnerabilities have been disclosed today. Four are buffer overflows in the Dnsmasq code that can lead to remote code execution scenarios, while the other three bugs allow DNS cache poisoning.<\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/dnspooq-lets-attackers-poison-dns-cache-records\/\" class=\"lazy\" alt=\"dnspooq-cves.png\" data-original=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2021\/01\/19\/e871fa66-d40f-4012-825f-7f005991ae9c\/dnspooq-cves.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2021\/01\/19\/e871fa66-d40f-4012-825f-7f005991ae9c\/dnspooq-cves.png\" class alt=\"dnspooq-cves.png\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<h3>DNSpooq are easy to pull off, but noisy attacks<\/h3>\n<p>On their own, the danger from each is limited, but researchers argue they can be combined to attack any device with older versions of the Dnsmasq software.<\/p>\n<p>Attacks can be carried out quite easily against Dnsmasq installations directly exposed on the internet, but the JSOF team warns that devices on internal networks are also at risk if attackers relay the attack code via browsers or other (compromised) devices on the same network.<\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/dnspooq-lets-attackers-poison-dns-cache-records\/\" class=\"lazy\" alt=\"dnspooq-attacks.png\" data-original=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2021\/01\/19\/df794b43-fee0-4b04-810b-371c8e921f84\/dnspooq-attacks.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2021\/01\/19\/df794b43-fee0-4b04-810b-371c8e921f84\/dnspooq-attacks.png\" class alt=\"dnspooq-attacks.png\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<p>The attacks might sound hard to execute, but in an interview with&nbsp;<em>ZDNet&nbsp;<\/em>on Monday, Shlomi Oberman, chief executive officer at JSOF, said it was the contrary.<\/p>\n<p>&#8220;DNSspooq cache poisoning vulnerabilities are not hard to pull off and are the type of vulnerabilities that, in our opinion, could be easily automated and used by botnets, malvertisers, phisers, and that merry bunch,&#8221; Oberman said.<\/p>\n<p>&#8220;The main challenge for someone exploiting these vulnerabilities on a large scale is that they are quite noisy so they will probably be noticed by ISPs and other companies with wide visibility to internet traffic,&#8221; the JSOF CEO told&nbsp;<em>ZDNet<\/em>.<\/p>\n<p>Oberman added that the attacks also require sending many DNS packets to a targeted device, which also takes a lot of time, and, in addition, also requires that attackers have access to adequate attack infrastructure.<\/p>\n<p>Nonetheless, these are not prohibitive requirements, and the JSOF exec believes the DNSpooq attack is well in the reach of both cybercrime gangs and nation-state (APT) groups alike.<\/p>\n<h3>Patches rolling out everywhere<\/h3>\n<p>The easiest way to prevent any of these attacks would be to apply the security updates that will be released later today by the Dnsmasq project.<\/p>\n<p>However, many of these Dnsmasq DNS forwarding clients are included inside the firmware of other products, where end consumers can&#8217;t reach in and update just one single library.<\/p>\n<p>Oberman, whose company previously also discovered, disclosed, and helped patch the wide-reaching&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/ripple20-vulnerabilities-will-haunt-the-iot-landscape-for-years-to-come\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ripple20 vulnerabilities<\/a>, has taken a similar approach this time as well.<\/p>\n<p>The JSOF exec told&nbsp;<em>ZDNet&nbsp;<\/em>that his company has worked with both the Dnsmasq project author and multiple industry partners to make sure patches were made available to device vendors by today&#8217;s public disclosure.<\/p>\n<p>&#8220;The disclosure process included forming a task group composed of security and engineering representatives from Cisco, Google, Red-Hat, Pi Hole, CERT\/CC, Simon Kelley (Dnsmasq maintainer), and JSOF,&#8221; Oberman told us.<\/p>\n<p>&#8220;The task force engaged on how to record the vulnerabilities, how to communicate them, and also suggested several different patches. There are now patches available under embargo, both as a new version and as backported patches,&#8221; he added.<\/p>\n<p>CERT\/CC and ICS-CERT also helped coordinate disclosing the DNSpooq attacks to other vendors not included in the original task force. While some vendors might be late with integrating the patches, most vendors have been notified by now about the seven vulnerabilities and their need to eventually deploy patches to all affected products. A list of affected vendors, products, and patches (if available), are listed on the official <a href=\"https:\/\/www.jsof-tech.com\/disclosures\/dnspooq\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">DNSpooq website<\/a>.<\/p>\n<h3>End-users have their own countermeasures<\/h3>\n<p>But for end consumers, determining which vendor deployed DNSpooq patches will most likely be an impossible feat, even for those with advanced technical skills.<\/p>\n<p>Chasing down CVE identifiers for the seven DNSpooq vulnerabilities in device firmware changelogs is a complex feat even for security professionals and software engineers, let alone the average Joe.<\/p>\n<p>Oberman says that these users can protect themselves against DNSpooq-vulnerable devices on their network through two methods.<\/p>\n<p>&#8220;A good workaround would be to use DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT),&#8221; Oberman said.<\/p>\n<p>&#8220;Another option would be to statically configure a trusted DNS server, like Cloudflare or Google DNS servers, so that DNS requests are not handled by the home router and go directly to the [remote] DNS server.<\/p>\n<p>&#8220;Both these options require some technical understanding, but are simple enough for many users to carry out,&#8221; Oberman told us.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31943\/DNSpooq-Lets-Attackers-Poison-DNS-Cache-Records.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":39198,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[9162],"class_list":["post-39197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackerdnsflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DNSpooq Lets Attackers Poison DNS Cache Records 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DNSpooq Lets Attackers Poison DNS Cache Records 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-19T14:26:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/01\/dnspooq-lets-attackers-poison-dns-cache-records.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"515\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"DNSpooq Lets Attackers Poison DNS Cache Records\",\"datePublished\":\"2021-01-19T14:26:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/\"},\"wordCount\":978,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/dnspooq-lets-attackers-poison-dns-cache-records.png\",\"keywords\":[\"headline,hacker,dns,flaw\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/\",\"name\":\"DNSpooq Lets Attackers Poison DNS Cache Records 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/dnspooq-lets-attackers-poison-dns-cache-records.png\",\"datePublished\":\"2021-01-19T14:26:56+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/dnspooq-lets-attackers-poison-dns-cache-records.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/dnspooq-lets-attackers-poison-dns-cache-records.png\",\"width\":1000,\"height\":515},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dnspooq-lets-attackers-poison-dns-cache-records\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,dns,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerdnsflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DNSpooq Lets Attackers Poison DNS Cache Records\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DNSpooq Lets Attackers Poison DNS Cache Records 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/","og_locale":"en_US","og_type":"article","og_title":"DNSpooq Lets Attackers Poison DNS Cache Records 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-01-19T14:26:56+00:00","og_image":[{"width":1000,"height":515,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/01\/dnspooq-lets-attackers-poison-dns-cache-records.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"DNSpooq Lets Attackers Poison DNS Cache Records","datePublished":"2021-01-19T14:26:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/"},"wordCount":978,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/01\/dnspooq-lets-attackers-poison-dns-cache-records.png","keywords":["headline,hacker,dns,flaw"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/","url":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/","name":"DNSpooq Lets Attackers Poison DNS Cache Records 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/01\/dnspooq-lets-attackers-poison-dns-cache-records.png","datePublished":"2021-01-19T14:26:56+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/01\/dnspooq-lets-attackers-poison-dns-cache-records.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/01\/dnspooq-lets-attackers-poison-dns-cache-records.png","width":1000,"height":515},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/dnspooq-lets-attackers-poison-dns-cache-records\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,dns,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerdnsflaw\/"},{"@type":"ListItem","position":3,"name":"DNSpooq Lets Attackers Poison DNS Cache Records"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=39197"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39197\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/39198"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=39197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=39197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=39197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}