US-CERT Warns of Impending DNS Cache Poisoning

LOS ANGELES — The United States Computer Emergency Readiness Team (US-CERT) is warning website owners and operators about deficiencies in the Domain Name Server (DNS) protocol which may leave affected systems vulnerable to DNS cache poisoning attacks.

According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.

This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.

US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.

A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.

While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.

US-CERT will provide additional information as it becomes available.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

SkyPrivate Announces New Communications Options

SkyPrivate has announced new communications options as alternatives to Skype, which Microsoft is retiring in May.

Cruel Reell Joins Pineapple Support as Supporter-Level Sponsor

Cruel Reell has joined the ranks of over 60 adult businesses and organizations committing funds and resources to Pineapple Support.

TEAs Show Hosts Defiant Celebration as Community Unites Amid Uncertainty

There was celebration in the air at the 2025 Trans Erotica Awards on Sunday night, but beneath the evening's festivities ran a strong undercurrent of defiance.

2025 TEAs Winners Announced

Winners of the 2025 Trans Erotica Awards (TEAs) were revealed Sunday night during an invitation-only event at Avalon nightclub in Hollywood.

NYU Study Finds Age Verification Laws Don't Work

A group of university researchers has published a study whose findings suggest that age verification laws are ineffective at achieving their stated goal of preventing minors from accessing adult content.

XVideos Loses Advertiser Reporting Appeal in EU Court

Web Group Czech Republic (WGCZ), parent company of XVideos, has lost an appeal in the top EU court to be temporarily exempted from a requirement to publish a list of the site's advertisers.

2025 Pornhub Awards to Be Held May 8 in Los Angeles

The seventh annual Pornhub Awards will take place May 8 in Los Angeles.

Illinois Lawmakers Propose Decriminalizing Consensual Sex Work

Lawmakers in Illinois have introduced a bill that would completely decriminalize consensual sex work in the state.

VR Bangers Joins Pineapple Support as Supporter-Level Sponsor

VR Bangers has joined the ranks of over 60 adult businesses and organizations committing funds and resources to Pineapple Support.

Missouri House Gives Initial Approval to Age Verification Bill

The Missouri House of Representatives has given initial approval to HB 236, the state's proposed age verification law.

Show More