1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

DNS server attacks begin using BIND software flaw

Discussion in 'Network World' started by RSS, Aug 3, 2015.

  1. RSS

    RSS New Member Member

    Attackers have started exploiting a flaw in the most widely used software for the DNS (Domain Name System), which translates domain names into IP addresses.

    Last week, a patch was issued for the denial-of-service flaw, which affects all versions of BIND 9, open-source software originally developed by the University of California at Berkeley in the 1980s.

    The flaw can be exploited with a single packet, crashing both authoritative and recursive DNS servers. Security analysts predicted that attackers would quickly figure out how to exploit the flaw, which has now happened.

    “We can confirm that the attacks have begun,” wrote Daniel Cid, CTO and founder of the security company Sucuri. “DNS is one of the most critical parts of the Internet infrastructure, so having your DNS go down, it also means your email, HTTP and all other services will be unavailable.”

    To read this article in full or to leave a comment, please click here

    Continue reading...

Share This Page