AplusWebMaster
Topic Starter
FYI…
- http://news.com.com/2102-7349_3-5816061.ht…g=st.util.print
August 3, 2005
"…In a scan of 2.5 million so-called Domain Name System machines, which act as the White Pages of the Internet, security researcher Dan Kaminsky found that about 230,000 are potentially vulnerable to a threat known as DNS cache poisoning. "That is almost 10 percent of the scanned DNS servers," Kaminsky said in a presentation last week at the Black Hat security event in Las Vegas. "If you are not auditing your DNS servers, please start," he said. The motivation for a potential attack is money, according to the SANS Internet Storm Center… There are about 9 million DNS servers on the Internet, Kaminsky said. Using a high-bandwidth connection provided by Prolexic Technologies, he examined 2.5 million. Of those, 230,000 were identified as potentially vulnerable, 60,000 are very likely to be open to this specific type of attack, and 13,000 have a cache that can definitely be poisoned. The vulnerable servers run the popular Berkeley Internet Name Domain software in an insecure way and should be upgraded, Kaminsky said. The systems run BIND 4 or BIND 8 and are configured to use forwarders for DNS requests–something the distributor of the software specifically warns against. BIND is distributed free by the Internet Software Consortium. In an alert on its Web site, the ISC says that there "is a current, wide-scale…DNS cache corruption attack." All name servers used as forwarders should be upgraded to BIND 9, the group said…"
Download BIND 9 (Current Release BIND 9.3.1):
- http://www.isc.org/index.pl?/sw/bind/

- http://news.com.com/2102-7349_3-5816061.ht…g=st.util.print
August 3, 2005
"…In a scan of 2.5 million so-called Domain Name System machines, which act as the White Pages of the Internet, security researcher Dan Kaminsky found that about 230,000 are potentially vulnerable to a threat known as DNS cache poisoning. "That is almost 10 percent of the scanned DNS servers," Kaminsky said in a presentation last week at the Black Hat security event in Las Vegas. "If you are not auditing your DNS servers, please start," he said. The motivation for a potential attack is money, according to the SANS Internet Storm Center… There are about 9 million DNS servers on the Internet, Kaminsky said. Using a high-bandwidth connection provided by Prolexic Technologies, he examined 2.5 million. Of those, 230,000 were identified as potentially vulnerable, 60,000 are very likely to be open to this specific type of attack, and 13,000 have a cache that can definitely be poisoned. The vulnerable servers run the popular Berkeley Internet Name Domain software in an insecure way and should be upgraded, Kaminsky said. The systems run BIND 4 or BIND 8 and are configured to use forwarders for DNS requests–something the distributor of the software specifically warns against. BIND is distributed free by the Internet Software Consortium. In an alert on its Web site, the ISC says that there "is a current, wide-scale…DNS cache corruption attack." All name servers used as forwarders should be upgraded to BIND 9, the group said…"
Download BIND 9 (Current Release BIND 9.3.1):
- http://www.isc.org/index.pl?/sw/bind/