What security risks are involved in recursive DNS?
Through a carefully-crafted attack, it is possible to make a caching DNS server add incorrect DNS information to its cache memory. An attacker can therefore redirect users attempting to access a particular resource, say a financial institution website, and send them to a malicious site that collects personal account information. This attack is fairly difficult, and the exact number of successful cache poisoning attacks is not known.