Re: [Full-disclosure] bind-9.8.1 remote code exec exploit?



Hello

On 29.10.2011 15:34, nix@xxxxxxxxxxxxxxxx wrote:

I've source compile of BIND 9.8.1 on the server.

Is this bind server used as authoritative server for some DNS
domains? Or does your configuration allow to be queried from the
whole internet for resolving?

I've been investigating weird iptables messages as follows:

Oct 29 14:53:13 NIX kernel: IN= OUT=eth0 SRC=MY_SERVER_IP DST=62.80.128.29
LEN=114 TOS=0x00 PREC=0x00 TTL=64 ID=31795 PROTO=UDP SPT=53 DPT=5060
LEN=94

I received a message from my ISP abuse that my server is scanning SIP port
5060 and I set the firewall rule to deny/log all UDP connections out of
the box to port 5060 to get timestamps for further investigation. This
happened before I set the firewall rule.

For me this above log messages looks like a regular answer from
your DNS server to the client (or a resolving DNS server) running
on the destination IP address.

A DNS request runs like this:
A client (or resolving DNS server) does a query through UDP from
his source port 5060 (could be any other random port) to the
server on port 53. As UDP is connectionless, the server is
sending the answer back from his UDP port 53 to the destination
port 5060.


bye
Fabian

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... The name.local entries are used by my apache server to implement ... change button, more button, the "Primary DNS suffix of this ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • Issues migrating SBS 2003 domain to Server 2008 Standard
    ... We are stuck migrating our SBS 2003 domain to Server 2008. ... Fatal Error:DsGetDcName (SRV-EXCH) call failed, ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant access web on local network server
    ... Yes my Windows 2003 R2 Standard Server is a DC domain controller. ... How do I open DNS for the outside? ... What port should I give access to? ...
    (microsoft.public.windows.server.general)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... button, more button, the "Primary DNS suffix of this computer", it should ... The Security System could not establish a secured connection with the server ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • Virtual host "lite"?
    ... redirect an incoming we request based on DNS name, ... "http://webmail.domain.com " will automatically be redirected to port ... fall over and the Boss works out what a "server" is.. ...
    (comp.os.linux.networking)