‘Poisoned’ DNS Servers an Increasing Risk

LAS VEGAS — Security experts warn that up to 10 percent of the Internet’s Domain Name System (DNS) servers are vulnerable to cache poisoning, in which hackers trick a DNS server into redirecting legitimate traffic to bogus sites.

Security researcher Dan Kaminsky performed a scan of 2.5 million of the Internet’s visible DNS servers and found 230,000 servers that could be exploited. Cache poisoning occurs when hackers successfully corrupt the cache of a DNS, populating its memory with directions to malware servers.

The servers in the most danger are those running earlier versions of the Berkeley Internet Name Domain software (BIND). These early versions employ blind forwarding, which is the loophole potential cache poisoners seek.

Kaminsky spoke at this week’s Black Hat Security conference in Las Vegas. “If you are not monitoring your DNS activity, it is time to start,” he said. DNS servers, which resolve URLs like “https://www.xbiz.com" into numerical IP addresses, often are found at the ISP level, so they handle tens of thousands of user requests daily.

Once a DNS server is poisoned by being tricked into “trusting” another server is legitimate, all subsequent requests for a particular URL will be redirected to, perhaps, an adware or malware site. As hackers are often paid for the volume of traffic they redirect, larger and larger DNS servers are targeted.

Kaminsky performed his scan of the Internet’s DNS servers in July and has not pinpointed which of the web’s server clusters are most vulnerable.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Arizona Governor Vetoes 'Protect Act' With New Consent Provisions

Arizona Governor Kate Hobbs on Friday vetoed HB 2133, the “Protect Act,” which would have imposed new requirements for adult content uploaded online.

Brazil Begins Monitoring 18 Adult Sites for AV Compliance

Brazil’s National Data Protection Authority (ANPD) is now monitoring 18 high-traffic adult websites for compliance with the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires such sites to age-verify users located in Brazil.

Ofcom Fines First Time Videos $100,000 for AV Noncompliance

U.K. media regulator Ofcom on Thursday imposed a fine of 80,000 pounds (more than $100,000) against First Time Videos, which operates FTVGirls.com and FTVMilfs.com, for failing to implement age checks required for compliance with the Online Safety Act.

Curves Ahead: How BBW Creators are Turning Differentiation Into Competitive Advantage

For centuries, curves have been celebrated as a symbol of beauty, sensuality and power. From the soft opulence of Rubens paintings to the glamorous silhouettes of pinup icons, fuller figures have long occupied a place in art, fashion and fantasy.

Woodhull Freedom Foundation to Host Virtual 'Pride' Edition of 'Fact Checked' Series

Woodhull Freedom Foundation is hosting a Pride Month virtual edition of its series “Fact Checked by Woodhull.”

'InMelanin' Relaunches Through PAYSITE

InMelanin.com has officially relaunched through PAYSITE.

Pearl Industry Network Partners With Takedown Piracy

Industry trade group Pearl Industry Network (PiN) has officially partnered with Takedown Piracy.

Hollywood Reporter Spotlights XBIZ Miami in Feature on Fan Platforms

Last month's XBIZ conference serves as the setting for a new Hollywood Reporter feature examining the competitive fan platform market.

F2F, Image Angel Launch 'Forensic Watermarking' for Traceability

Friends2Follow (F2F) and Image Angel have partnered to launch a new traceability solution to combat unauthorized content sharing with the use of forensic watermarks.

EU Court: France Can Require Foreign Sites to Implement AV

The European Union’s Court of Justice ruled on Tuesday that France may require pornographic websites based in other EU states to implement age verification in accordance with French law, as long as France follows EU electronic commerce rules.

Show More