US-CERT Warns of Impending DNS Cache Poisoning

LOS ANGELES — The United States Computer Emergency Readiness Team (US-CERT) is warning website owners and operators about deficiencies in the Domain Name Server (DNS) protocol which may leave affected systems vulnerable to DNS cache poisoning attacks.

According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.

This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.

US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.

A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.

While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.

US-CERT will provide additional information as it becomes available.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

DarkFans Rolls Out 'Configure Limits' Solution

DarkFans has debuted its Configure Limits monetization solution for creators.

Clips4Sale, Free Speech Coalition Partner for 'Creator Workflow' Webinar

Clips4Sale (C4S) and Free Speech Coalition (FSC) have partnered for a webinar titled “Organization & Workflow: Simple Systems for Busy Creators.”

Pineapple Support, Streamate Partner for 'Self-Parenting' Support Group

Pineapple Support and Streamate are hosting a free online support group focused on self-care for performers, titled "Self-Parenting: Becoming Your Own Safe Space."

Nerds of Porn to Relaunch Site Through MyMember.site

Nerds of Porn is relaunching its membership site through MyMember.site on Aug. 14.

SCREEN Act Back in Play: Federal AV Bill Faces Senate Hearing

The U.S. Senate Committee on Commerce, Science, and Transportation has slated a markup session this week for the SCREEN Act, which would mandate site-based age verification of users accessing adult content online on a national level.

Clips.com Launches Lifetime Creator Referral Program

Recently launched creator platform Clips.com has introduced its new lifetime creator referral program.

BranditScan Rolls Out 'Leak Detection' Update

BranditScan has updated its Leak Detection feature for OnlyFans creators.

Arcom Targets 31 Adult Sites Over Age Verification

French media regulator Arcom on Wednesday announced that it is taking action against 31 adult websites that the agency says have failed to implement age verification as required under France’s Security and Regulation of the Digital Space (SREN) law.

AEBN Publishes Popular Searches for May, June

AEBN has published the top search terms for May and June from its straight and gay theaters in all 50 states and the District of Columbia.

Show More