Slashdot Mirror


"DNS Forgery Pharming" Attack Against BIND 9

Monley writes "Help Net Security is running a story about a severe flaw in BIND's implementation that allows fraudsters to efficiently predict generated random numbers without the need to control the route between the user and the DNS server. (Here are HTML and PDF versions of the paper.) Using this vulnerability, fraudsters can remotely forge DNS responses and direct users to fraudulent websites, which can steal the user's sign-in credentials and do other mischief. The flaw was discovered by security researcher and Trusteer's CTO, Amit Klein." The ISC has released a patch to BIND 9.

6 of 105 comments (clear)

  1. Re:Yes but... by Anonymous Coward · · Score: 1, Informative

    Only clueless (windows) admins will install and run bind nowayday. There you go...

  2. Re:New by e9th · · Score: 3, Informative
    This weakness of BIND has been griped about for TEN YEARS!

    http://www.openbsd.org/advisories/res_random.txt http://cr.yp.to/djbdns/forgery-cost.txt

  3. Re:Complexity breeds problems. by Kreggan · · Score: 3, Informative

    Frankly, yes. The basic concepts of a DNS server are fairly straightforward, but as demonstrated by this attack, the devil is in the details. This attack uses reasonably advanced cryptanalysis, and exploits the predictable behaviour of DNS clients. I suspect that this attack would also have been mitigated by the use of DNSSEC, but the roll-out of that has been held up for years - and DNSSEC itself introduces even more cryptographic complexity.

  4. Re:wow... by Anonymous Coward · · Score: 2, Informative



    OpenBSD's patched and native Bind9 is immune to this attack and has been for many years.

  5. Re:Don't Diss Bind by SaDan · · Score: 2, Informative
  6. Re:Jeezus freaking A Christ by TheRaven64 · · Score: 2, Informative

    Probably because BIND has to be cross-platform. I'm sorry to break this to you Matt, but some people use inferior operating systems without good random number generation function.

    --
    I am TheRaven on Soylent News