ASM and DNS Resolution: Dealing with DNS Poisoning at Scale
Listen now
Description
In this more technical episode, we dive deep into the complexities of DNS and DNS resolution in the context of Attack Surface Management (ASM). Join us as we explore the unseen challenges that arise when scaling asset discovery, particularly when dealing with DNS wildcards and their implications for security scanning solutions. Our hosts, Michael and Shubs, share their extensive experiences in managing DNS resolution at scale, discussing the importance of accurate asset discovery and the pitfalls of relying solely on IP-centric approaches. They highlight the significance of DNS data in understanding attack surfaces and the need for robust wildcard detection to filter out junk assets effectively. We also touch on the technical challenges faced when building a reliable DNS resolution infrastructure, the limitations of popular cloud providers like AWS, and the importance of observability in ensuring accurate results. Additionally, we share insights from a recent presentation on DNS poisoning at scale, revealing how unexpected patterns can lead to significant security implications. Topics Covered: The importance of DNS resolution in ASMChallenges with DNS wildcards and asset discoveryIP-centric vs. DNS-centric approachesBuilding a reliable DNS resolution infrastructureInsights on DNS poisoning and its implications
More Episodes
Running an effective bug bounty program requires balancing an attractive scope and payout to hunters with an attack surface that challenges hunters to do more than automated scans. Program managers want to pay for skillful findings, not automated ones. In this episode, we talk about how ASM helps...
Published 10/10/24
Published 10/10/24
In this episode, we discuss the blindspots of IP-centric approaches to asset discovery and the importance of understanding the full attack surface of an organization. We unpack the challenges posed by modern cloud architectures, load balancers, and WAFs, and how these can create blind spots in...
Published 10/02/24