On GameFAQs: The top 100 most popular games!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 3, 2005 11:00:00 AM

Hundreds of thousands of Internet servers are at risk of an attack that would redirect unknowing Web surfers from legitimate sites to malicious ones.

In a scan of 2.5 million so-called Domain Name System machines, which act as the White Pages of the Internet, security researcher Dan Kaminsky found that about 230,000 are potentially vulnerable to a threat known as DNS cache poisoning.

"That is almost 10 percent of the scanned DNS servers," Kaminsky said in a presentation last week at the Black Hat security event in Las Vegas. "If you are not auditing your DNS servers, please start," he said.

The motivation for a potential attack is money, according to the SANS Internet Storm Center, which tracks network threats. Attackers typically get paid for each spyware or adware program they manage to get installed on a person's PC.

How does DNS get poisoned?

There are a few steps to go through before a DNS server starts redirecting Web surfers to bogus sites.

Most people's PCs access a DNS server at an Internet service provider or within a company to map text-based Internet addresses to actual IP addresses. One DNS server can be used by thousands of Internet users.

For performance reasons, DNS servers cache the returned data, so that it takes less time to respond to the next request. When a DNS cache is poisoned, it affects all future lookups of the affected domain, for everyone who uses that particular DNS server.

To poison a DNS server:
• First, the target machine has to be tricked into querying a malicious DNS server set up by the attacker. This can be done, for example, by sending an e-mail message to a nonexistent user at the target ISP. Another way is to send an e-mail with an externally hosted image to an actual user.

• The target DNS server will then query the attacker's DNS server. In the DNS reply, the scammer includes extra data that will poison the victim's DNS cache. The extra information can be a malicious URL or even an entire domain space, such as .com.

• If the target DNS server is not configured properly, it will accept the new numerical IP listing and delete the proper entry.

• Once this has occurred, any queries sent to the DNS server for the affected URLs will be redirected to the replacement IP addresses set by the attacker. If a domain space is poisoned, all queries ending in that domain will be redirected.

Source: SANS Internet Storm Center, CNET News.com

Information lifted from victims, such as social security numbers and credit card data, can also be sold. Additionally, malicious software could be installed on a PC to hijack it and use it to relay spam.

The DNS servers in question are run by companies and Internet service providers to translate text-based Internet addresses into numeric IP addresses. The cache on each machine is used as a local store of data for Web addresses.

In a DNS cache poisoning attack, miscreants replace the numeric addresses of popular Web sites stored on the machine with the addresses of malicious sites. The scheme redirects people to the bogus sites, where they may be asked for sensitive information or have harmful software installed on their PC. The technique can also be used to redirect e-mail, experts said.

As each DNS server can be in use by thousands of different computers looking up Internet addresses, the problem could affect millions of Web users, exposing them to a higher risk of phishing attack, identity theft and other cyberthreats.

The poisoned caches act like "forged street signs that you put up to get people to go in the wrong direction," said DNS inventor Paul Mockapetris, chairman and chief scientist at secure DNS provider Nominum. "There have been other vulnerabilities (in DNS) over the years, but this is the one that is out there now and one for which there is no fix. You should upgrade."

There are about 9 million DNS servers on the Internet, Kaminsky said. Using a high-bandwidth connection provided by Prolexic Technologies, he examined 2.5 million. Of those, 230,000 were identified as potentially vulnerable, 60,000 are very likely to be open to this specific type of attack, and 13,000 have a cache that can definitely be poisoned.

The vulnerable servers run the popular Berkeley Internet Name Domain software in an insecure way and should be upgraded, Kaminsky said. The systems run BIND 4 or BIND 8 and are configured to use forwarders for DNS requests--something the distributor of the software specifically warns against.

BIND is distributed free by the Internet Software Consortium. In an alert on its Web site, the ISC says that there "is a current, wide-scale...DNS cache corruption attack." All name servers used as forwarders should be upgraded to BIND 9, the group said.

DNS cache poisoning is not new. In March, the attack method was used to redirect people who wanted to visit popular Web sites such as CNN.com and MSN.com to malicious sites that installed spyware, according to SANS.

"If my ISP was running BIND 8 in a forwarder configuration, I would claim that they were not protecting me the way they should be," Mockapetris said. "Running that configuration would be Internet malpractice."

The new threat--pharming
Kaminsky scanned the DNS servers in mid-July and has not yet identified which particular organizations have the potentially vulnerable DNS installations. However, he plans to start sending e-mails to the administrators of those systems, he said in an interview.

"I have a couple hundred thousand e-mails to send," he said. "This is the not-fun part of security. But we can't limit ourselves to the fun stuff. We have to protect our infrastructure."

The use of DNS cache poisoning to steal personal information from people by sending them to spoofed sites is a relatively new threat. Some security companies have called this technique pharming.

Poisoning DNS cache isn't hard, said Petur Petursson, CEO of Icelandic DNS consultancy and software company Men & Mice. "It is very well doable, and it has been done recently," he said.

Awareness around DNS issues in general has grown in the past couple of years, Petursson said. Four years ago, Microsoft suffered a large Web site outage as a result of poor DNS configuration. The incident cast a spotlight on the Domain Name System as a potential problem.

"It is surprising that you still find tens of thousands or hundreds of thousands vulnerable servers out there," Petursson said.

Kaminsky's research should be a wake-up call for anyone managing a DNS server, particularly broadband Internet providers, Mockapetris said. Kaminsky said he doesn't intend to use his research to target vulnerable organizations. However, other, less well-intentioned people could run scans of their own and find attack targets, he cautioned.

"This technology is known to a certain set of the hacker community, and I suspect that knowledge will only get more widespread," Mockapetris said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 93 Talkback(s)
linux is the culprit
http://www.analogstereo.com/dodge_durango_owners_manual.htm... (Read the rest)
Posted by: Apple ipod Posted on: 05/28/07 You are currently: a Guest | | Terms of Use
DNS servers--an Internet Achilles heel  Loverock Davidson | 08/03/05
You crack me up!  Patrick Jones | 08/03/05
OMG!!!1111eleventyone!!!!11  rpmyers1 | 08/03/05
I LIKE CAKE!!1!  Loverock Davidson | 08/03/05
BIND doesn't run the internet?? N/T  rpmyers1 | 08/03/05
No  Loverock Davidson | 08/03/05
So what software are those servers running?  rpmyers1 | 08/03/05
RE: Just the servers you listed dippy  bystander_z | 08/03/05
LOL!  CobraA1 | 08/03/05
More precisely  Yagotta B. Kidding | 08/03/05
Oh heavens no  Loverock Davidson | 08/03/05
Oh heavens no  communications@... | 08/03/05
tomorrows report:  linuxoverwindows | 08/03/05
If thats the case  Loverock Davidson | 08/03/05
If thats the case  communications@... | 08/03/05
tomorrows report:  communications@... | 08/03/05
The truth be told  kelkins@... | 08/04/05
linux is the culprit  Apple ipod | 05/28/07
Even worse.. XP often uses outside Nameservers.  thetruth_z | 08/03/05
Um..  Patrick Jones | 08/03/05
Not exactly...  thetruth_z | 08/03/05
It is not just XP..  Patrick Jones | 08/03/05
But, you don't think like a hacker.. (easy prey)  thetruth_z | 08/03/05
You are correct, I don't think like a hacker.  Patrick Jones | 08/03/05
BIG MISTAKE! Does your boss know?  jrbeaman | 08/03/05
youre kidding, right?  linuxoverwindows | 08/03/05
Re: It is not just XP..  none none | 08/03/05
Yes, you are correct..  Patrick Jones | 08/03/05
Replies just from the queried server? Maybe not.  johnay | 08/03/05
Interesting..  Patrick Jones | 08/03/05
Yeah, But ... This is Not the Assertion in the Post  PMC-CON | 08/03/05
Replies just from the queried server? Maybe not.  communications@... | 08/03/05
correction?  johnay | 08/17/05
Re: It is not just XP..  communications@... | 08/03/05
unconfigured-for and unpredictable behavior  Apple ipod | 05/28/07
The client querys the server.  bjbrock | 08/03/05
Ahh... yes.. Another person duped by M$  thetruth_z | 08/04/05
i run my own dns server  linuxoverwindows | 08/03/05
Doesn't really matter..  thetruth_z | 08/03/05
Could you be wrong? Funny, when our dns server is down  John Zern | 08/03/05
i use my isp primary dns...  linuxoverwindows | 08/03/05
Could you be wrong? Funny, when our dns server is down  communications@... | 08/03/05
Urban Legend? Source of this Assertion?  PMC-CON | 08/03/05
You've got it wrong..  thetruth_z | 08/03/05
Oh wide-mouthed one....  Scrat | 08/03/05
Because of course  frgough@... | 08/03/05
thoroughly fact-checked  Apple ipod | 05/28/07
RE: Oh wide-mouthed one....  Linux User 147560 | 08/03/05
actually...  psychodave | 08/03/05
doesn't have to  John Zern | 08/03/05
UNICES!!!!  s_gamgee | 08/04/05
Question for you thetruth  toadlife | 08/03/05
Totally wrong!!!  bjbrock | 08/03/05
They don't have to be down..  thetruth_z | 08/04/05
Congrats Mr truth - you've made it into my hall of shame!  toadlife | 08/04/05
correction  toadlife | 08/04/05
Lets get practical  LGLisle | 08/03/05
Surely you jest  Otto_Delete | 08/03/05
i work for an isp...  linuxoverwindows | 08/03/05
i work for an isp...  communications@... | 08/03/05
Partial "HEAR HEAR"...  s_gamgee | 08/04/05
we can talkback later  MIS Master | 08/03/05
OK, how about now  rpmyers1 | 08/03/05
Shooting the driver  Roger Ramjet | 08/03/05
You must think more menacing happy  Patrick Jones | 08/03/05
move zig for great justice!  linuxoverwindows | 08/03/05
why dns at all?  pesky_z | 08/03/05
Actually  DemonX | 08/03/05
DNS servers are for professionals. You arn't one.  jrbeaman | 08/03/05
correct folder and settings  Apple ipod | 05/28/07
Nice thought, but ...  dalecosp | 08/03/05
youre kidding, trolling or what?  linuxoverwindows | 08/03/05
why dns at all?  communications@... | 08/04/05
Is BIND the problem?  Yagotta B. Kidding | 08/03/05
BIND  vandy | 08/03/05
Direct consecuence of lazy admins  eduardo.carriles@... | 08/03/05
Quite possibly...  dalecosp | 08/03/05
Amazing!  kbeaumont | 08/03/05
I hate to say this but  Roger Ramjet | 08/03/05
DDNS  Yagotta B. Kidding | 08/03/05
Oh please give me a break  kokuryu | 08/03/05
can you wake me...  linuxoverwindows | 08/03/05
Thank you very much sir  toadlife | 08/03/05
99 % think without knowing the problem completely.  jolumoar | 08/03/05
Is the rest %1 thinking AND know the problem  michael_t | 08/04/05
Interesting way to deal with pharming (and phishing)  chrishanson | 08/03/05
but cannot deal with pharting....;-) nt  michael_t | 08/04/05
Unacceptable that some DNS servers are NOT patched yet  michael_t | 08/03/05
Maybe if all you Linux guys took a break ...  ShadeTree | 08/04/05
We do always update since  michael_t | 08/04/05
And for everyone's viewing pleasure, here is another reason to upgrade....  michael_t | 08/05/05
conspicuous place  Apple ipod | 05/28/07
More reason to distrust the internet  asthorpe@... | 08/05/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here