<?xml version="1.0" encoding="UTF-8"?>
<response>
  <status>success</status>
  <result>
    <project>
      <id>66523</id>
      <name>nsrx</name>
      <created_at>2008-12-18T23:29:58Z</created_at>
      <updated_at>2008-12-18T23:29:59Z</updated_at>
      <description>This is a proof-of-concept implementation of Dan Kaminsky's so-called &quot;DNS source routing&quot; hack.

WHAT IT DOES: establish inbound IP traffic to a host inside a private network, with no public IP address nor DNAT setup.

HOW IT WORKS: the private network's local dns resolver is fooled into relaying trafic back in forth.

REQUIREMENTS:
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The target network must host a local dns resolver
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The dns resolver must be able to establish UDP/53 connections towards the target
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The attacker must have authority on a zone somewhere in the DNS hierarchy
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The attacker must trigger an initial DNS request for the zone he controls from inside the target network (there are many ways to do so)

More in-depth documentation will be included, as the available documentation is scarse to say the least.</description>
      <homepage_url>http://code.google.com/p/nsrx</homepage_url>
      <download_url></download_url>
      <url_name>nsrx</url_name>
      <user_count>0</user_count>
      <average_rating></average_rating>
      <rating_count>0</rating_count>
      <analysis_id></analysis_id>
      <licenses>
        <license>
          <name>bsd</name>
          <nice_name>BSD Copyright</nice_name>
        </license>
      </licenses>
    </project>
  </result>
</response>
