US-CERT Warns of Impending DNS Cache Poisoning

LOS ANGELES — The United States Computer Emergency Readiness Team (US-CERT) is warning website owners and operators about deficiencies in the Domain Name Server (DNS) protocol which may leave affected systems vulnerable to DNS cache poisoning attacks.

According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.

This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.

US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.

A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.

While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.

US-CERT will provide additional information as it becomes available.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

ASN Lifestyle Magazine Joins Pineapple Support as Media Sponsor

ASN Lifestyle Magazine has joined the ranks of over 60 adult businesses and organizations committing funds and resources to Pineapple Support, partnering with the organization as a media sponsor.

Adult Industry Reacts to Trump Victory

On Tuesday, former President Donald Trump was reelected, defeating Vice President Kamala Harris to reclaim the office he lost four years ago.

Fetisfy Online Fetish Marketplace Launches

Fetisfy.com, an online marketplace for users to sell fetish items, has launched.

Pineapple Support Launches 'Spill the Tea, Colombia' Community Support Event Series

Pineapple Support has launched "Spill the Tea, Colombia," a monthly, in-person community support event for adult industry professionals.

Streamster Launches 'Tip2Peep' Camera-Switching Feature

Live-streaming software provider Streamster has launched Tip2Peep, a new feature that allows viewers to switch between multiple webcam viewing angles by tipping the creator.

Tyler Wu Guests on Chaturbate's 'Sex Tales' Podcast

Tyler Wu is the latest guest on Chaturbate’s “Sex Tales” podcast, hosted by Melissa Stratton and Vanniall on the company’s “Camming Life” YouTube channel.

Fleshy to Launch Interactive Cam Site 'Eromote'

Male pleasure brand Fleshy has announced that it will launch an interactive, bidirectional cam site next month called Eromote.

XBIZ LA Show Introduces New 'Crib Crawl' Feature

XBIZ is pleased to announce that the 2025 edition of its flagship conference, the XBIZ Show, will debut a brand-new feature: Crib Crawl, offering attendees the chance to meet and greet representatives from leading brands and organizations in dedicated suites at the host venue.

Pre-Nominations Now Open for 2025 TEAs

The pre-nomination period for the 2025 Trans Erotica Awards (TEAs) is now open.

Byborg Invests $22.35M in PLBY Group

Luxembourg-based Byborg Enterprises SA is investing $22.35 million in Playboy parent company PLBY Group.

Show More