US-CERT Warns of Impending DNS Cache Poisoning

LOS ANGELES — The United States Computer Emergency Readiness Team (US-CERT) is warning website owners and operators about deficiencies in the Domain Name Server (DNS) protocol which may leave affected systems vulnerable to DNS cache poisoning attacks.

According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.

This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.

US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.

A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.

While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.

US-CERT will provide additional information as it becomes available.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Playboy Partners With Creator Platform Tango

Playboy has partnered with creator platform Tango, introducing Playmates to the livestreaming service.

Anti-Porn Senator Introduces Federal Age Verification Bill

U.S. Senator Jim Banks of Indiana, who last month urged the Department of Justice to ramp up obscenity prosecutions, on Wednesday introduced a bill that would make age verification by adult websites federal law.

AEBN Publishes Popular Searches by Country for April, May

AEBN has released the list of popular searches from its straight and gay theaters, by country, for April and May.

Ondato Joins Pineapple Support as Sponsor

Age and identity verification company Ondato has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

2026 XBIZ Amsterdam Website Now Live, Registration Opens

XBIZ is pleased to announce that the website for its annual European conference, XBIZ Amsterdam, is now live.

MyMember.site Integrates FSC's 'PrivateAV' Age Verification Solution

MyMember.site has integrated Free Speech Coalition's PrivateAV age verification tool into its website-building platform.

Pearl Industry Network Opens Beta for Creator Networking App

Industry trade group Pearl Industry Network (PiN) has launched beta testing for the PiN Member App, a networking and collaboration tool for content creators.

FSC: W.V. Age Verification Law Takes Effect June 12

The Free Speech Coalition has issued a reminder notice that West Virginia's age verification law takes effect on June 12, 2026.

Pineapple Support Taps Brad Mitchell, Jean-Micheal Veen for Senior Leadership Positions

Pineapple Support has named Brad Mitchell as its new board president and Jean-Micheal Veen as technology and development chair.

Polish Government Proposes AV Mandate for Adult Sites

Poland’s Council of Ministers on Tuesday endorsed a proposed national law that would require sites and platforms to age-verify users to prevent minors from accessing adult content online.

Show More