Amit Klein of Trusteer discovered and documented weakness in a way PowerDNS
Recursor generates DNS queries and transaction IDs used in DNS queries. This
weakness can be used to predict transaction IDs used in a subsequent queries
after observing certain amount of consequent previous queries, leading to a high
possibility of performing a successful cache poisoning attack.