NEWS STORY
US-CERT Warns of Impending DNS Cache Poisoning

45.22% |
45.22% |
9.57% |
According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.
This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.
US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.
A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.
While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.
US-CERT will provide additional information as it becomes available.
See all current articles in > adult industry news
Related Articles
RSS Feeds | E-Newsletters | Desktop Widget | Mobile
XBIZ Newswire > Adult industry news service for the media
XBIZ Premiere > Adult industry magazine for the retail market
VIDEO NEWS
ALTA Trade Group, Ideal Image Management Clash Over Licensing
CineKink Film Festival to Screen Brittany Andrews Documentary
West Coast Unveils 'Black Romance Color of Love'
Ron Jeremy Spied Shooting Horror Film
Tommy Gunn Launches Signature Line of Underwear
Video: Jenna Haze Retires From Performing
NOVELTY NEWS
Baci Lingerie Declares Success at Salon International de la Lingerie
Nasstoys Now Distributed by Pink Cherry
HPPPA Launches Toy Line, Taps ECN for Exclusive Distribution
Entrenue Brings Lovehoney’s Rock Box to U.S. Market
JOPEN Announces Intensity Insider Winner
Practice Safe Policy Launches Romney Condoms
RETAIL NEWS
Alabama’s Pleasures Store Hosting 2nd Annual Guns for Toys Event
Playboy Kicks Off Super Bowl With 'Carnival Mystique'
The Tranny Awards Moves to Hollywood, Calif.
Jimmy Flynt Opens New Store in Kentucky
Hustler Hollywood Store, Website Undergo Transformation
Italian Porn Stars Face Off in Mayoral Race
PROFILES & BIOS
WIA Profile: Jacky St. James
WIA Profile: Kay Brandt
Director’s Chair: James Avalon
multiple news outlets with 1 click.
add free content to your website.
with your mobile device.
|
|
XBIZ Miami
MikeSouth
|
|
There Goes The Neighborhood
LeRoy
|
|
are xxx already domains being used?
DotXXX
|
|
Top Ranked Users
SafeCharge EddieK
|
|
|
New Affiliate Rep and New at Xbiz
Jimmy aka Wizzo
|
|
|
Adult Entertainment Virtual Convention
Loki
|
|
Who else is looking forward to the Phoenix Forum?
Jim_Gunn
|
|
|
Getting questions coming in on Ad Agencies (selling space) for Adult
Black and Blue Media
|
|
Producers, What would you want to see in a clip site?
Varian Gray
|
|
|
New @ Xbiz
VinnyWTS
|
FIND PRODUCTS & SERVICES

UPCOMING EVENTS





All News / Editorial





























