Connect with us
X
Categories:

Technology

Unsecure DNS resolvers provide a significant danger of website hijack

Published

on

Unsecure DNS resolvers provide a significant danger of website hijack
Share this post:

Hidden DNS (domain name system) resolvers create a means for carrying out email redirection and account takeover attacks, security researchers warn.

In a technical blog post, SEC Consult explains how it’s possible to manipulate the DNS name resolution of these so-called closed DNS resolvers using a variant of cache poisoning attacks (PDF), which were first unveiled by celebrated network security researcher Dan Kaminsky way back in 2008.

Cache from chaos

Previous research by SEC Consult has shown how it’s possible for an attacker to take over user accounts of web applications by manipulating DNS name resolution.

Closed DNS resolvers are used by numerous hosting providers and other internet service providers (ISPs) to provision services to their clients. As the name suggests, closed DNS resolvers reside on closed networks or intranets.

However, ‘closed’ is a bit of a misnomer in the context of SEC Consult’s research because the researchers have shown how it might be possible for external actors to abuse the functionalities of web applications to readily attack closed resolvers.

They found that attack reconnaissance is possible by exploiting how closed DNS resolvers interact with spam protection mechanisms on the open internet.

This could help an attacker understand DNS security features like source port randomization, DNSSEC, IP fragmentation, and, more simply by exploiting registration, password-reset, as well as newsletter functionalities of web applications that rely on closed resolvers.

Scouring the web

SEC Consult used two open source tools – DNS Reset Checker and the DNS Analysis Server – to analyze DNS traffic from targeted systems in order to identify vulnerabilities.

In practical terms, this attack reconnaissance work involved sending emails to some well-known domains and specifying the analysis domain as the sending domain. This allowed the researchers to identify thousands of systems that used static source ports, a security oversight that left them vulnerable to Kaminsky-style attacks.

“After sending emails to roughly 50k domains, we’ve received and analyzed DNS data for approximately 7,000 of them,” SEC Consult explains. “Among those 7,000 domains, at least 25 were using static source ports. By going down the rabbit hole again, thousands of more domains using static source ports were discovered.”

None of a sample of 25 vulnerable resolvers were using or enforcing additional security features such as DNSSEC, SEC Consult discovered.

Affected services were running behind domains operated by both small and big businesses, and sites delivering governmental services and political campaigns.

DNS cache poisoning insecurities can be abused to manipulate records and redirect emails – a security shortcoming that would allow an attacker to abuse the password reset functionalities of WordPress and Joomla installations, among others.

RECOMMENDED  How To Collect Email Addresses From Web Pages

The attack technique can be used to hijack even a fully patched WordPress installation, SEC Consult was able to demonstrate.

The infosec firm has held back on publicly releasing the exploit code it developed to attack WordPress systems, because of concerns that awareness of the issue is low, which would leave many web-based systems accessible through closed DNS resolvers open to attack.

SEC consult spoke to ISPs, hosting providers, and computer emergency response teams (CERTs) about the issue in the months prior to going public with its findings last week.

Cache out

Independent DNS security experts said that the research highlighted a valid concern.

Cricket Liu, chief DNS architect at Infoblox, told Daily Swig: “I don’t think this is particularly novel – we talked about this sort of thing back in the heyday of the Kaminsky vulnerability – but it’s relevant because there are still some DNS servers out there that don’t use source port randomization.”

Containing exotic attacks

Even though legacy Kaminsky attacks are definitely not the ‘next big thing’ it would be unwise to dismiss the issue as unfashionable, according to SEC Consult.

Timo Longin, a security consultant at SEC Consult, told Daily Swig: “The DNS provides very exotic and unknown attack vectors that should be brought to the attention of the infosec community! For example, we found some hosting providers where it would potentially be possible to compromise all hosted servers by password-reset hijacking users via the providers’ control panel”.

To safeguard systems, vulnerable DNS resolvers must be patched and configured securely. Some best practices for securing your own DNS resolvers can be found at Google and at DNS flag day. Alternatively, large public DNS providers such as Google, Cloudflare, or Cisco can also be used.

Countermeasures for new DNS attacks are usually implemented quickly by these large providers, according to SEC Consult.


Get More Stories Like This On: Facebook: @AllNaijaEntertainment, Twitter: @AllNaijaEntertainment
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Lotus Car UK
Automobile3 hours ago

UK Brand Lotus Lowers Production Targets Due To Import Tariffs

Electric G-Wagon
Automobile3 hours ago

Electric G-Wagon Launches In UK With A Price Tag Of Over £180,000

Olumide Akpata
News3 hours ago

Edo guber: I answer to no godfather only Edo people – Olumide Akpata declares

Why Victor Osimhen of Napoli made fun of Verona supporters with a "funny" celebration
Sports3 hours ago

Chelsea: Al Ahli agree €80m fee for Osimhen, player to sign £646,000-a-week deal

Simon Ekpa
News2 days ago

Simon Ekpa fire back at Nigeria govt over extradition him from Finland

Atiku Abubakar
Education2 days ago

Under 18s limit for university, WAEC, NECO policy – Atiku react

Education2 days ago

WAEC, NECO will no longer allow under 18 – Nigerian Govt

Godwin Obaseki
News3 days ago

Group tell Obaseki to beg Oba of Benin for forgiveness

Lagos Red Line Train
Automobile3 days ago

Lagos Red Line To Begin Free Operation on Wednesday

PDP logo
News3 days ago

LG Election: Benue PDP Release Guidelines

WHO World Health Organization
Health3 days ago

WHO Unveil Budget For Monkey Pox

GDP
Business4 days ago

Nigeria’s GDP grew by 3.19% in Q2 2024 amid hardship

NYSC Service Corp Members
Education4 days ago

NYSC launches redeployment option for married female corps members

Black Market
News4 days ago

Fuel Scarcity: FRSC sends warning motorists against travelling with petrol in jerrycans

News4 days ago

Imo APC ward chairman arrested for allegedly selling FG’s palliative

Farm land
News4 days ago

Farmers lament in Adamawa as thieves plunder farms, steal crops

Chinese EVs
Automobile4 days ago

Market: Chinese EVs Are Thriving In Latin American Countries

VW Golf R year 20 Edition
Automobile4 days ago

Huge Fine Plies European Car Manufacturers

Electric Vehicle Charging
Automobile5 days ago

South Korea Bans Fully Charged Electric Vehicles Entering Underground Garages

Non-Tesla vehicles with CCS compatible models include the BMW i3, Kia e-Niro, and Jaguar I-Pace
Automobile5 days ago

Tesla Recalls Over 9,000 Cars In The US To Avoid Parts Falling Off the Roof

Volkswagen
Automobile5 days ago

Volkswagen Lowers Battery Production Targets

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids
Automobile6 days ago

Market Study: Electric Cars Are Too Expensive

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids
Automobile6 days ago

China Considers Import Tariffs On Foreign Vehicles

Everything To Know About Nigeria New Presidential Jet, Previous Users, Age & Cost
Automobile6 days ago

Everything To Know About Nigeria’s New Presidential Jet, Previous Users, Age & Cost

BMW Becomes Europe Most Popular EV Brand Overtakes Tesla
Automobile7 days ago

BMW Becomes Europe’s Most Popular EV Brand Overtakes Tesla

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids
Automobile7 days ago

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids

Benefits of Partnering with a Managed Security Service Provider
Technology3 months ago

Benefits of Partnering with a Managed Security Service Provider

Diya Cant Have Enough
Music4 months ago

[Music] Diya – “Can’t Have Enough” Feat G-Wills

Email Newsletter Marketing Online Website
Technology4 months ago

The Vital Role of Email Fraud Detection Software

Roisea: Most Advanced Crypto Trading Platform for Bitcoin
Business5 months ago

The Role of Regulation in Crypto Investment: Navigating Legal Frameworks

Volatility in Commodities and How to Deal with It
Business5 months ago

Volatility in Commodities and How to Deal with It

Expanding Living Space
Lifestyle7 months ago

Expanding Living Space: Prefabricated Workshop Building Kits for Extra Rooms

BeBe Winans
Lyrics7 months ago

BeBe Winans – It All Comes Down to Love [Lyrics]

BeBe Winans
Music7 months ago

[Music] BeBe Winans – It All Comes Down to Love

The Countdown Begins to the Tournament That Has It All
ANE Football Analytical8 months ago

AFCON 2023: A Sporting Spectacle Set to Captivate the World

Litecoin: What Makes It The Crypto Winner?
Technology9 months ago

Runny Inflation Can Drive Cryptocurrency Adoption

Black and White French Bulldog puppies Frenchie Joy
Lifestyle9 months ago

Black and White French Bulldog puppies Frenchie Joy

3 Serious Reasons to Keep Your Teenager Away From Social Media
Lifestyle9 months ago

3 Serious Reasons to Keep Your Teenager Away From Social Media

Boxing vs MMA What Makes Them So Different
Sports10 months ago

Boxing vs MMA: What Makes Them So Different

Roisea: Most Advanced Crypto Trading Platform for Bitcoin
Technology10 months ago

NFTs and Intellectual Property Rights: Shaping Creative Ownership

Everything To Know About Nigeria New Presidential Jet, Previous Users, Age & Cost
Automobile6 days ago

Everything To Know About Nigeria’s New Presidential Jet, Previous Users, Age & Cost

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids
Automobile6 days ago

China Considers Import Tariffs On Foreign Vehicles

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids
Automobile6 days ago

Market Study: Electric Cars Are Too Expensive

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids
Automobile7 days ago

Ford Cancels Its Three-Row Electric SUV Focuses On Hybrids

BMW Becomes Europe Most Popular EV Brand Overtakes Tesla
Automobile7 days ago

BMW Becomes Europe’s Most Popular EV Brand Overtakes Tesla

VW Golf R year 20 Edition
Automobile4 days ago

Huge Fine Plies European Car Manufacturers

Chinese EVs
Automobile4 days ago

Market: Chinese EVs Are Thriving In Latin American Countries

Volkswagen
Automobile5 days ago

Volkswagen Lowers Battery Production Targets

Non-Tesla vehicles with CCS compatible models include the BMW i3, Kia e-Niro, and Jaguar I-Pace
Automobile5 days ago

Tesla Recalls Over 9,000 Cars In The US To Avoid Parts Falling Off the Roof

Electric Vehicle Charging
Automobile5 days ago

South Korea Bans Fully Charged Electric Vehicles Entering Underground Garages

Farm land
News4 days ago

Farmers lament in Adamawa as thieves plunder farms, steal crops

Black Market
News4 days ago

Fuel Scarcity: FRSC sends warning motorists against travelling with petrol in jerrycans

NYSC Service Corp Members
Education4 days ago

NYSC launches redeployment option for married female corps members

WHO World Health Organization
Health3 days ago

WHO Unveil Budget For Monkey Pox

News4 days ago

Imo APC ward chairman arrested for allegedly selling FG’s palliative

GDP
Business4 days ago

Nigeria’s GDP grew by 3.19% in Q2 2024 amid hardship

Lagos Red Line Train
Automobile3 days ago

Lagos Red Line To Begin Free Operation on Wednesday

PDP logo
News3 days ago

LG Election: Benue PDP Release Guidelines

Education2 days ago

WAEC, NECO will no longer allow under 18 – Nigerian Govt

Why Victor Osimhen of Napoli made fun of Verona supporters with a "funny" celebration
Sports3 hours ago

Chelsea: Al Ahli agree €80m fee for Osimhen, player to sign £646,000-a-week deal

Olumide Akpata
News3 hours ago

Edo guber: I answer to no godfather only Edo people – Olumide Akpata declares

Electric G-Wagon
Automobile3 hours ago

Electric G-Wagon Launches In UK With A Price Tag Of Over £180,000

Godwin Obaseki
News3 days ago

Group tell Obaseki to beg Oba of Benin for forgiveness

Atiku Abubakar
Education2 days ago

Under 18s limit for university, WAEC, NECO policy – Atiku react

Simon Ekpa
News2 days ago

Simon Ekpa fire back at Nigeria govt over extradition him from Finland

Lotus Car UK
Automobile3 hours ago

UK Brand Lotus Lowers Production Targets Due To Import Tariffs

ANE Billboard Hots