[ news_security_news ] DNS Attack Threat May Be Overstated
David Utter Staff Writer
2006-03-21
Insider Reports RSS Feed
The simplicity of how attackers can turn thousands of domain name servers against a target not only boggles the mind but constitutes a tremendous threat to Internet resources; however, the vulnerability may be more a matter of poorly configured machines.
Some may consider the MSNBC report on DNS and its role in attacks to overstate the problem. In looking at Bob Sullivan's assessment of the issue, it appears some work needs to be done to safeguard sites from criminal misuse of the DNS system.
Sullivan likens the attack to the prank of phoning in a fake pizza delivery order to someone's house. Person A asks Business B to deliver to Person C, which it does. Online, it is called a spoof attack.
Local domain name servers are the ones being used to facilitate these attacks. Sullivan noted how DNS traffic tends to be trusted by sites, and shutting down a site's access to other sites because of the DNS traffic coming from it punishes users at that site without solving the problem.
So far, it sounds like the obvious solution is to unplug one's computer, switch from direct deposit at work to receiving one's paycheck in gold coins, and wait patiently for the apocalypse.
Maybe not.
Commenters on Sullivan's story pointed out that the attacks he referenced hit DNS machines using BIND. Poorly configured systems using BIND offer the opportunity for exploitation as Sullivan reported. However, BIND can be hardened to withstand these types of attacks.
Sullivan interviewed Paul Vixie, the creator of BIND for the article. A commenter named Karl Denninger took Vixie to task for the whole issue:
There are technological fixes available for the DNS issues. Vixie and his group (ISC) are the AUTHORS and MAINTAINERS of that code. Indeed, 90% of what he's complaining about is addressed with fixes already in there - but which are turned off BY DEFAULT. WHY Paul? WHY?
If you're reading this, administering BIND, and haven't hardened the installation, this may be a good time to start.
---
Tag: DNS
Add to | DiggThis | Yahoo! My Web
Get all the updates in RSS:
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More news_security_news Articles
Insider Reports RSS Feed
|
|