Re: DNS cache poisoning?

From: David Pick (d.m.pick_at_qmul.ac.uk)
Date: 08/17/05

  • Next message: Rabinowitz, Michael CTR MDA/ION: "RE: DNS cache poisoning?"
    To: incidents@securityfocus.com
    Date: Wed, 17 Aug 2005 07:44:34 +0100
    
    

    > Your first step should be to remove your DNS services
    > from that WinNT box to something that is less vulnerable and
    > start using a BIND based DNS solution
    <snip>

    I'd agree wholeheartedly with the first part of this. But:

    There are other DNS servers available for UNIX/Linux that are
    even less vulnerable than BIND. BIND is pretty good, but still
    has "features" that are unnecessary and any unnecessary code
    can contain vulnerabilities. I use a package called "DJBDNS"
    (see: http://cr.yp.to/) that is a little more work to set up
    but which, one running, is *very* stable. It's also easier to
    keep the zone files maintained: they're a different format
    from BIND, but simpler to update.

    One thing that many people find makes DJBDNS harder is that
    it uses different programs for running a DNS cache and for
    supplying master sources of DNS data, so for most people
    both have to be set up, but each is individually easier to
    set up *safely* than BIND. It is also much more conservative
    than BIND about adding the "additional" records in a response
    to the cache, and this makes it almost impossible to poison
    the cache program.

    Just my 2p-worth. don't get the impression BIND is dangerous:
    it isn't; but it is possible to do even better.

    -- 
    	David Pick
    

  • Next message: Rabinowitz, Michael CTR MDA/ION: "RE: DNS cache poisoning?"

    Relevant Pages

    • Re: DNS Poisoning, pharming, pollution
      ... running Windows 2003 and have the "secure cache against pollution" setting ... the next thing to look for would be a malicious program on the server. ... >> Every server is configured with our ISP's DNS resolvers as forwarders. ... but I don't think we're running BIND. ...
      (microsoft.public.windows.server.dns)
    • CERT Advisory CA-2002-31 Multiple Vulnerabilities in BIND
      ... Multiple vulnerabilities with varying impacts have been found in BIND, ... normal operation of your name server, ... BIND DNS Server Vulnerabilities ...
      (Cert)
    • [NEWS] BIND 9 DNS Cache Poisoning
      ... BIND 9 DNS Cache Poisoning ... source UDP port and DNS transaction ID can be effectively predicted. ... address of the target name server), and the destination UDP port (53 the ...
      (Securiteam)
    • [UNIX] Multiple Remote Vulnerabilities in BIND4 and BIND8
      ... ISS X-Force has discovered several serious vulnerabilities in the Berkeley ... Internet Name Domain Server (BIND). ... majority of DNS servers on the Internet. ... deployed recursive DNS servers on the Internet. ...
      (Securiteam)
    • Re: DNS Manipulation via IPTables or other means?
      ... You might use the BIND view functionality ... I thought I could alter DNS responses ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
      (Security-Basics)