Home » Server

This DNS server is vulnerable!

17 July 2008 2 views No Comment

The at IP address 202.188.0.132 is susceptible to a attack. The is not changing its source port, query id, or both, between queries. This means it is easier than average for an attacker to spoof responses to queries from this , causing the to serve a potentially malicious record in response to any query.

Click here for more details on this and how to patch it.

If you are not in control of your own , contact your provider but do not be unduly concerned in the near term. IT administrators have only recently been apprised of this issue, and should have time to safely evaluate and deploy a fix.

Address Query source port Query ID
202.188.0.132 32791 15158
202.188.0.132 32791 51989

Based on the results, the is vulnerable if the IPs AND the source ports match, or the query IDs match. Matching query source ports or query IDs make it easier to spoof fake results to the , its .

We encourage you to run DNSreport to make sure your is configured properly. This comprehensive health check runs 55 tests against your , pinpoints the issue and offers mitigation steps on how to fix it. You can automate this report with DNSalerts - we will monitor your around-the-clock and notify you via email if problems arise.

Note: This critical flaw was discovered by Dan Kaminsky, Director of Testing for IOActive. To learn more, visit doxpara.com.

Tags: , , , , , ,

Related posts

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.