Hi, this is Jonathan Spring with my colleague Leigh Metcalf. For some time now, we’ve been working through a problem we found, but it’s time to discuss it more broadly. Using our passive DNS data source, we can observe cache poisoning. What we really observe are changes in the answers that are returned for certain domains, but after consulting with various experts, we believe the only behavior these changes indicate is a successful cache poisoning attack.
more here............http://www.cert.org/blogs/certcc/post.cfm?EntryID=206
more here............http://www.cert.org/blogs/certcc/post.cfm?EntryID=206