DNS servers 'vulnerable to attack'

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

Pharming, Secunia

NEWS

Many DNS servers are wrongly configured or running out-of-date software, leaving them vulnerable to malicious attacks, according to a survey published on Monday.

The Measurement Factory, an Internet performance firm, warned that Internet Systems Consortium's BIND software, which performs the domain name resolution function, is out-of-date on a fifth of DNS servers — which underpin the Internet by translating domain names into IP addresses.

DNS servers which run BIND versions lower than 9 are 'opening the door' to pharming attacks through DNS cache poisoning, The Measurement Factory claimed.

DNS cache poisoning involves hacking into DNS servers and replacing the numeric addresses of legitimate Web sites with the addresses of malicious sites. Internet users are then redirected to fake Web pages where they may be asked for information such as bank account details or unwittingly have spyware installed on their PCs.

Thomas Kristensen, chief technical officer of security company Secunia, told ZDNet UK it was likely that 20 percent of DNS servers were running out-of-date software, as the survey claimed, but he downplayed the risk of vulnerabilities being exploited.

"It should be noted that the 8.x and 4.x versions [of BIND] aren't vulnerable as such, but they were designed in a manner which makes them unsuitable for use as forwarders in specific DNS server setups. If these servers are used in a setup where they are used as forwarders then it is possible to conduct cache poisoning attacks against them," said Kristensen.

Kristensen added that Internet Systems Consortium strongly recommends against using 4.X and 8.X versions of BIND as forwarders.

A DNS server stores the numerical addresses of legitimate Web sites in a cache. DNS forwarders will forward queries onto other name servers if it does not have the necessary information to resolve these requests itself.

This process is known as "recursive name service", as the DNS server will push its request up the hierarchy of DNS servers until it reaches one that can resolve it.

The Measurement Factory surveyed 1.3 million DNS servers, and found that more than three quarters of them allow recursive name service to "arbitrary queriers", rather than from trusted users. This will open a name server up to malicious attacks, according to the report.

In theory, once a malicious hacker has compromised one DNS server, it could use the recursive name service to force other DNS servers to contact the compromised server to resolve a request. Over time, this would allow the hacker to poison the caches of a large number of DNS servers, via the cache of one compromised machine.

Recursive name services should only be enabled on a DNS server for a restricted list of trusted requestors, according to Inblox, the infrastructure developer that commissioned the survey.

Kristensen concurred. "It is not a good idea to allow arbitrary people to do recursive queries as it makes cache poisoning and denial-of-service attacks much more likely. Generally, recursive queries should only be allowed from specific IP addresses."

ISPs should only provide DNS services to their own customers, according to Kristensen. "Generally, all users who connect to the Internet using other connections than leased lines and business class xDSL lines, are dynamically assigned IP addresses, gateways and DNS servers each time they log on," he said.

Malicious hackers who wanted to compromise DNS servers through the recursive name services feature would need to know how various DNS servers are linked together. They could do this by requesting a zone transfer — a query that asks a name server which other servers are contained within its 'zone'.

The Measurement Factory's survey found that over 40 percent of DNS servers also allow zone transfers from arbitrary queriers. The survey claims this exposes a name server to DoS attacks and gives attackers information about internal networks.

Secunia agreed this was also a bad idea.

"Opening a name server for zone transfers does very often expose an excessive amount of information about "secret" hosts, internal hosts, gateway configuration, and much more. This kind of information may prove very useful for a malicious person wishing to conduct an attack," Kristensen said.

Zone transfers should only be allowed by internally controlled secondary name servers, according to Secunia.

"Zone transfer is something that should only be used between trusted name servers for zones in which they are authoritative. Zone transfer is not the mechanism which should be used between untrusted name servers," said Kristensen.

Inblox has advised IT professionals to take these six steps to mitigate against DNS vulnerabilities:

  1. If possible, split external name servers into authoritative name servers and forwarders.
  2.  

  3. On external authoritative name servers, disable recursion. On forwarders, allow only queries from your internal address space.
  4. If you can't split your authoritative name servers and forwarders, restrict recursion as much as possible. Only allow recursive queries if they come from your internal address space.
  5. Use hardened, secure appliances instead of systems based on general-purpose servers and operating software applications.
  6. Make sure you run the latest version of your domain name server software.
  7. Filter traffic to and from your external name servers. Using either firewall- or router-based filters, ensure that only authorized traffic is allowed between your name servers and the Internet.

Talkback

This again? Is this a new article about an old problem, or did you simply dust off an article from 3 years ago.

Oh woe is us! Users at risk! DNS unsafe! This issue came up and was dealt with several years ago. DNS poisoning, use to be an issue and use to be reported along with the virus du jor but, the problem was fixed and that is why we don't hear about DNS poisoning anymore.

DNS servers 'vulnerable to attack' Get over yourself!

via Facebook 26 October, 2005 14:32
Reply

Grumpy, you forget that plenty of admins out there don't get passed behind the Next, Next, Finish install because that was how what they bought got sold.
Sure, that leaves plenty of room for all sorts of problems but until you figure out to make it a real problem on paper the decision makers involved simply can't be bothered with it.

via Facebook 27 October, 2005 23:10
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

35 minutes ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

9 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

10 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

11 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

13 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

14 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

15 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

16 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

17 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

19 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint