On CHOW: Can girls use the guys' bathroom?
BNET Business Network:
BNET
TechRepublic
ZDNet

July 23rd, 2008

Attack code published for DNS flaw

Posted by Ryan Naraine @ 2:55 pm

Categories: Arbitrary Code Execution, Botnets, Browsers, Data theft, Exploit code, Locally Running Web Servers, Metasploit, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Zero-day attacks

Tags: DNS, Exploit, Attack, Flaw, Domain Names, Networking, Internet, Ryan Naraine

Exploit posted for DNS cache poisoning vulnerability The urgency to patch Dan Kaminsky’s DNS cache poisoning vulnerability just went up a few notches.

Exploit code for the flaw, which allows the insertion of malicious DNS records into the cache of the target nameserver, has been added to Metasploit, a freely distributed attack/pen-testing tool.

According to Metasploit creator HD Moore (left), who teamed up with researcher |)ruid to create the exploit, a DNS service has also been created to assist with the exploit.

[ SEE: Vulnerability disclosure gone awry: Understanding the DNS debacle ]

The code, available here, takes aim at known deficiencies in the DNS protocol and common DNS implementations that aid in serious cache poisoning attacks.

This exploit caches a single malicious host entry into the target nameserver.  By causing the target nameserver to query for random hostnames at the target domain, the attacker can spoof a response to the target server including an answer for the query, an authority server record, and an additional record for that server, causing target nameserver to insert the additional record into the cache.

In an IM exchange, Moore told me his exploit takes about a minute or two to poison a DNS cache but said he is working to improve it in version 2.0.

Kaminsky in on record as saying it is possible to launch a successful attack in a matter of seconds.

Patch now! Please.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 31 Talkback(s)
correct...
An it department has nothing else to do throughout the day, perhaps there was a deployment schedule that, had the original time-line of privacy been kept, would have met the deadline without any probl... (Read the rest)
Posted by: whitetigersx Posted on: 07/29/08 You are currently: a Guest | | Terms of Use
Irresponsible and evil  Stan57 | 07/23/08
Quote: "What positive will come of this?"  dunn@... | 07/24/08
Assumption  Stan57 | 07/24/08
And yet, you assume...  elnyka | 07/24/08
hmmmm....  whitetigersx | 07/29/08
Assumption (of your own)  ZDNET_guest666 | 07/24/08
wrong  ysangkok@... | 07/24/08
RE: Irresponsible and evil  GreyGeek | 07/24/08
pad time...  whitetigersx | 07/29/08
I can't think of ANYONE who deserves to be...  flatliner | 07/23/08
Oh grow up cowboy! Ignorance is not bliss.  dunn@... | 07/24/08
No, but keeping the script kiddies & uneducated but resourceful terrorist.  invmgr@... | 07/24/08
Godwins Law, but now on terrorists?  alecco | 07/25/08
Publish just 2 days & the attacks are on. Maybe I was right, hmmm?  invmgr@... | 07/29/08
So What  KStads | 07/23/08
AGREED, and it gives you test code....  dunn@... | 07/24/08
true but,  whitetigersx | 07/29/08
RE: Attack code published for DNS flaw  jamalystic | 07/24/08
For those of you..  supercharlie | 07/24/08
Just plain dumb  Stan57 | 07/24/08
huh?  whitetigersx | 07/29/08
Held Responsible  Shayd | 07/24/08
I'm afraid you misunderstand, Shayd  JediMercer | 07/24/08
right...Fear Mongering  Shayd | 07/25/08
You're right...  whitetigersx | 07/29/08
There are losers everywhere.  lschw1 | 07/24/08
Attackers, watch your back.  Ngallendou | 07/24/08
Slight error in logic  ich1 | 07/24/08
RE: Attack code published for DNS flaw  mel@... | 07/25/08
What??  psychosmurf | 07/27/08
correct...  whitetigersx | 07/29/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here