BIND flaws not fixed after five years

The most recent vulnerabilities identified in BIND and several other Domain Name Server implementations, including Microsoft and Apple variants, may not be fixable, and were identified in security vulnerabilities as long ago as 1997.

Some security consultants are now saying that these DNS vulnerabilities represent a flaw in the DNS protocol itself, and cannot be eliminated entirely. At least one leading expert has said "...thinking that software can protect you... with the current DNS protocol is like thinking that shorts and a T-shirt will protect you from the winter wind in Chicago."

The comment appeared in a message posted to "bugtraq", a security related mailing list.

Security advisories released in April 1997 by Secure Networks Inc. and Core Seguridad outlined, and addressed, the same vulnerability as was documented and published by CAIS and CERT last week.

A simple fix, which could have been used minimise the vulnerabilities, was determined years ago as a result of discussions and development that occurred in response to the 1997 advisories being released.

A security "patch" for BIND was written to resolve issues raised in the 1997 advisory. Comments in the code make note that "...brute force attempts are entirely feasible" and then go on to make a very simple technical note of how to minimise the impact of the vulnerabilities.

It is unclear why so many DNS implementations are still vulnerable to an attack that was clearly outlined in advisories and discussions more than five years ago.

Domain Name Servers (DNS) match Internet domain names to numerical Internet Protocol (IP) addresses, somewhat like a phone book matching names to phone numbers. The most recently reported vulnerabilities make it possible for an attacker to fudge the information contained in a DNS, hence redirecting Internet users to bogus IP addresses.

Advertisement

Talkback 1 comments

    So much for the much-touted th ...Andrew Constance -- 04/12/02

    So much for the much-touted theory that open-source software will save us from all these woes; the truth is that most newbie script-kiddies who want to play with Linux and other non-MS OS's can't program for nuts - which includes reading (let alone fixing!) the code of other programmers.

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured