GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Upgrade your DNS: BIND 9 DNS Vulnerability / DDoS Attack (https://gfy.com/showthread.php?t=918605)

CYF 07-28-2009 09:39 PM

Upgrade your DNS: BIND 9 DNS Vulnerability / DDoS Attack
 
There's a new exploit for BIND 9 that will allow a remote attacker to shut down your DNS servers.

The exploit is in the wild, all versions are affected.

There is a patch / upgrade available.

Text from www.isc.org:

Redwood City, California -- July 28, 2009 -- ISC has published new releases of all current versions BIND 9 in response to CERT Vulnerability Note VU#725188. See this ISC Security Advisory for details and instructions for downloading these releases.

An exploit of this vulnerability was made public at the same time the vulnerability was announced, which makes it especially important to upgrade.

Receipt of a specially-crafted dynamic update message may cause BIND 9 servers to exit. This vulnerability affects all servers ? it is not limited to those that are configured to allow dynamic updates. Access controls will not provide an effective workaround.

Some sites may have firewalls that can be configured with packet filtering techniques to prevent nsupdate messages from reaching their nameservers.

CYF 07-28-2009 09:41 PM

For the technical details see here:

https://www.isc.org/node/474

Urgent: this exploit is public. Please upgrade immediately.

Barefootsies 07-28-2009 09:45 PM

bump for the urgency!

CYF 07-28-2009 09:58 PM

Quote:

Originally Posted by Barefootsies (Post 16117434)
bump for the urgency!

This is pretty serious, the exploit code is 25 lines of perl code. It's out in the wild.

OrangeContent 07-28-2009 10:04 PM

That's no fun at all.

CYF 07-28-2009 10:33 PM

Quote:

Originally Posted by OrangeContent (Post 16117457)
That's no fun at all.

No, it's not very fun. Bind is a very popular DNS server and this allows anyone on the internet to kill your dns server.

CYF 07-29-2009 03:26 PM

bmping some important into

alias 07-29-2009 03:27 PM

Tinydns?


All times are GMT -7. The time now is 05:53 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123