[REVS] DNS Cache Snooping
From: SecuriTeam (support_at_securiteam.com)
Date: 05/04/04
- Previous message: SecuriTeam: "[UNIX] XSS and Path Disclosure in Network Query Tool"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 4 May 2004 15:47:50 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
DNS Cache Snooping
------------------------------------------------------------------------
SUMMARY
Linked below is a research paper discussing several aspects of DNS Cache
Snooping and how they can be prevented.
DETAILS
Abstract:
This research paper presents a technical overview of the technique known
as DNS cache snooping. By first doing a brief introduction to DNS,
followed by a discussion on common misconceptions regarding DNS
sub-systems.
Then this relatively unknown technique is introduced, followed by a field
study to assert the overall exposure of the Internet to this threat. In
addition, a set of devised abuse scenarios that rely on cache snooping are
presented.
This paper concludes with recommendations on how to reduce exposure to
this problem, including proposed changes to the BIND DNS server
implementation.
The paper discusses two ways of spoofing the DNS cache, using
Non-recursive queries, or by parsing TTL with Recursive queries.
After this, several abuse scenarios are presented, and methods to protect
the DNS cache from spoofing, with a practical example of BIND
configuration file.
ADDITIONAL INFORMATION
The paper can be found at:
<http://community.sidestep.pt/~luis/DNS-Cache-Snooping/>
http://community.sidestep.pt/~luis/DNS-Cache-Snooping/
The information has been provided by <mailto:demz@geekz.nl> demz.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[UNIX] XSS and Path Disclosure in Network Query Tool"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|