Home > News > US-CERT Warns of Impending DNS Cache Poisoning • Bookmark   • Newsletters   • Register Search Options

NEWS STORY

US-CERT Warns of Impending DNS Cache Poisoning

US-CERT Warns of Impending DNS Cache Poisoning
Get XBIZ News
XBIZ Research
Should governments have the power / ability to stop content piracy? (e.g. SOPA / PROTECT IP)
Yes
  45.22%
No
  45.22%
Undecided
  9.57%
Out of 230 votes. Results based on votes submitted by members of XBIZ.net social network.
Wednesday, Jul 23, 2008    Text size: 
LOS ANGELES — The United States Computer Emergency Readiness Team (US-CERT) is warning website owners and operators about deficiencies in the Domain Name Server (DNS) protocol which may leave affected systems vulnerable to DNS cache poisoning attacks.

According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.

This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.

US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.

A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.

While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.

US-CERT will provide additional information as it becomes available.

More ways to get XBIZ News:  RSS Feeds  |  E-Newsletters  |  Desktop Widget  |  Mobile
Looking for porn star news and behind-the-scene videos? Check out XFANZ.com !

LEGAL PERSPECTIVES

Need for Serious Value in Content

Most adult entertainment business owners know that distributing sexually explicit materials exposes them to the possibility of prosecution for violation of obscenity laws. But while many know that the... More »

Romney? Perry? 5 Things to Prepare for

It’s the fall of 2011, and the U.S. unemployment rate is at 9.1 percent and the economy appears too many to be heading back into recession. It is not surprising that President Obama’s approval... More »

Killing the Messenger: The Campaign Against Online Escort Advertising Sites

The recent guilty plea by Escorts.com has ignited interest in the legal issues surrounding the operation of an online escort site.  In this two-part blog post, the author will examine real-world examples... More »
XBIZ NEWSLETTERS
Stay informed of the latest industry developments. Get XBIZ newsletters delivered to your inbox. Subscribe today!
Enter email address:

* To manage existing subscriptions click here.






POPULAR PRODUCTS & SERVICES
Submit your press release to
multiple news outlets with 1 click.
Subscribe to RSS news feeds or
add free content to your website.
Access XBIZ news and articles
with your mobile device.
Access the latest issues of the industry's premier trade journals in digital format - view online or download for offline viewing!

UPCOMING EVENTS

XBIZ London Gathering

Feb 23 - Feb 23
Truckles Wine Bar in Holborn

Adult Entertainment Virtual Convention

Feb 24 - Feb 26
World Wide Web

The European Summit

Mar 05 - Mar 08
Barcelona, Spain

International Lingerie Show

Mar 26 - Mar 28
Las Vegas, Nevada
Everyday thousands of business professionals browse XBIZ's industry directory for quality products and services. Not listed yet? Your company could be losing potential new business. Submit your company today!
Use XBIZ RSS feeds to stay informed of the latest industry developments or as a content syndication tool for your website!