Domain name registries are scrambling to patch a newly discovered bug in popular open source DNS software that could be exploited for denial-of-service attacks.
The bug and a corresponding fix were announced Monday by NLnet Labs, a research group that provides authoritative domain name server software called NSD to domain name registrars.
The bug allows for an attack on an NSD server that would cause it to stop responding to queries. The bug affects all versions of NSD 2.0.0 to 3.2.1, NLnet Labs said calling the bugfix "critical."
The bug is a "one-byte buffer overflow that allows a carefully crafted exploit to take down your name server," NLnet Labs said.
The NSD bug is not the result of a problem with the DNS protocol, nor does it have implications for the rollout of DNS security software known as DNSSEC. That's why it's a minor incident compared to the Kaminsky bug discovered last summer.
"This bug is serious in so much that it allows an attacker to [make] name servers stop working, but the patch is readily available," says Dave Knight, Director of Resolution Services at Afilias, which operates the .info and .org domains. "We don't think there have been any attacks in the wild."
Knight said that now the bug is public knowledge, hackers can reverse engineer it to build an exploit.
"Patching should be a priority for everyone running NSD," Knight said.
Afilias runs several authoritative software packages, including NSD and BIND. Knight said Afilias was patching its NSD servers, which will be fixed by the end of the week.
"We also run BIND and other DNS software, so we are not necessarily vulnerable to an attack or threat on any one platform," said John Kane, vice president of Afilias. "Some registries only have one platform, which makes them more vulnerable and requires them to do an emergency patch. In our case, we can flip and run only BIND if we need to for awhile, and then we have the luxury of deploying the bug fix on NSD after it's been tested and passed Q/A."
- Recommend:
- 0 Comments
New DNS Bug and Fix Announced
For more information about enterprise networking, go to NetworkWorld. Story copyright 2011 Network World Inc. All rights reserved.
- Sponsored Resource: Do-it-yourself guide to home networking.
- Sponsored Resource: How to choose the right server for your business.
- Sponsored Resource: How to protect your PCs and servers in minutes.
Read more like this: bugs, online security
-
Lenovo IdeaPad
See why the IdeaPad tablet is optimized for ultimate entertainment.
Business News Daily
Get the latest technology news that's important to you and your business, fresh seven days a week.
Latest in Business Center Blogs
-
Security Alert - February 14, 2012 1:56 PM
Microsoft Says 'Happy Valentine's Day' with Nine Security Bulletins As expected, Microsoft has released nine security bulletins today. Security researchers and experts offer guidance on which updates are the most urgent.
-
Simply Business - February 14, 2012 12:19 PM
Sync Your Outlook Data Among Multiple PCs Astonsoft's EZOutlookSync makes simple work of synchronizing your contacts, calendars, notes, e-mail, and more. And you can test-drive it free for 30 days.
-
Linux Line - February 14, 2012 10:28 AM
Five Good Reasons to Download LibreOffice 3.5 Targeting power users, this new release of the free, open source office productivity suite is built to be 'cleaner, leaner, and more feature-rich'.
-
Net Work - February 14, 2012 9:37 AM
Samsung Galaxy Tab 2 Doomed by Price? If the leaked pricing for the Galaxy Tab 2 turns out to be true, the poor tablet is doomed to fizzle before it even launches.
-
Linux Line - February 14, 2012 8:39 AM
Six Ways to Show Your Love for Free Software Today Valentine's Day is also 'I Love Free Software Day,' according to the Free Software Foundation Europe, and there are many ways you can take part.
-
Net Work - February 14, 2012 7:45 AM
Microsoft India Store a Victim of Poor Data Security, Not Hackers Customer data from the online Microsoft Store in India was compromised by hackers, but the blame lies with shoddy data security practices.
Featured Webcasts
-
Top 10 Concerns of Buying a VoIP Business Phone System

Type: whitepaper
Company: CompareBusinessProducts.com
Categories: VOIP
-
Buying a Phone System? Compare the 94 Business Phone Systems in One Chart

Type: whitepaper
Company: CompareBusinessProducts.com
Categories: VOIP













Comments