INForum.in - Home of the Indian Domain Industry
Results 1 to 6 of 6
  1. #1
    pubdomains.in is offline Senior Member
    Join Date
    Oct 2008
    Location
    Bits & Byte
    Posts
    183
    Thanks
    44
    Thanked 81 Times in 51 Posts

    Lightbulb ISC BIND 9 vulnerable to denial of service via dynamic update request

    The Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS) implementation from Internet Systems Consortium (ISC). It includes support for dynamic DNS updates as specified in IETF RFC 2136. BIND 9 can crash when processing a specially-crafted dynamic update packet. ISC notes that this vulnerability affects all servers that are masters for one or more zones and is not limited to those that are configured to allow dynamic updates. ISC also indicates that the attack packet has to be constructed for a zone for which the target system is configured as a master; launching the attack against slave zones does not trigger the vulnerability.


    CERT
    ISC

  2. #2
    Jeff's Avatar
    Jeff is offline Administrator
    Join Date
    Mar 2008
    Posts
    2,996
    Thanks
    1,780
    Thanked 474 Times in 277 Posts

    Default Re: ISC BIND 9 vulnerable to denial of service via dynamic update request

    Can you translate that into English

  3. #3
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Default Re: ISC BIND 9 vulnerable to denial of service via dynamic update request

    Quote Originally Posted by Jeff View Post
    Can you translate that into English
    Whew, I thought I was the only one who could not understand a word of that.

    Pubdomains.in, I'm guessing you're an expert in this area if you're able understand all that technical jargon.
    Last edited by Ceres; 07-31-2009 at 01:02 AM.

  4. #4
    pubdomains.in is offline Senior Member
    Join Date
    Oct 2008
    Location
    Bits & Byte
    Posts
    183
    Thanks
    44
    Thanked 81 Times in 51 Posts

    Default Re: ISC BIND 9 vulnerable to denial of service via dynamic update request

    Okies - first need to understand few basics
    a. DOS attack - Denial - Of - Service : When legitimate websites are loaded with fake requests (like continuous ping to a server from 1000 machines - so that CPU gets loaded enough to stop processing other requests and eventually crashes out)

    b. DNS System: Used for resolving names. Thus InForum.in translates to an IP address, and this translation from user friendly language specific words to machine readable quad IP address such as 67.228.108.241 for inforum.in

    c. BIND9: Berkeley Internet Name Domain (BIND) is a popular Domain Name System (DNS). Used by multiple nameservers all across the globe.

    --------------------
    What the article posted by CERT advises is that a number of DNS systems using BIND9 could crash by use of malicious code that has been identified.

    Directly you or I may not be controllling name servers - unless we have setup our own NameServers or DNS System. Since All website owners depend upon one or the other name servers for address resolution of our sites - there is a potential problem if the nameservers are not patched for possible DOS attack.

    Good news is, that most of the name servers have been patched now after the warning was issued - and you shouldn't face any problems unless you own a DNS system and have not upgraded it to patch the hole.

    HTH!!

  5. The Following 2 Users Say Thank You to pubdomains.in For This Useful Post:

    Ceres (07-31-2009),Jeff (08-04-2009)

  6. #5
    Ceres's Avatar
    Ceres is offline Senior Member
    Join Date
    Mar 2008
    Location
    Canada
    Posts
    2,206
    Thanks
    544
    Thanked 576 Times in 347 Posts

    Default Re: ISC BIND 9 vulnerable to denial of service via dynamic update request

    Hey thanks pubdomains.in. I understand now!

  7. #6
    Jeff's Avatar
    Jeff is offline Administrator
    Join Date
    Mar 2008
    Posts
    2,996
    Thanks
    1,780
    Thanked 474 Times in 277 Posts

    Default Re: ISC BIND 9 vulnerable to denial of service via dynamic update request

    Thanks pubdomains.in!

 

 

Similar Threads

  1. Replies: 1
    Last Post: 12-28-2008, 07:10 AM
  2. Replies: 0
    Last Post: 12-18-2008, 04:01 PM
  3. MakeOK.com - Price 2000$
    By universe in forum Non-India Related Domains
    Replies: 0
    Last Post: 12-10-2008, 01:02 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •