FINDING · EVALUATION

DNS hijacking via shared VPN NAT is feasible because the full 16-bit TxID space (up to 65,536 values) can be brute-forced in an average of 4.27 seconds, well within a typical 10-second DNS request timeout; browser DNS cache windows range from 60 seconds (Chrome/Edge) to 660 seconds or more (Firefox), with longer windows enlarging the injection race window.

From 2026-yang-invisible-adversaries-systematicInvisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNs · §III-C, §IV-D, Table I · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.