Skip Links

How to block Microsoft DNS exploit

Dr. Internet By Steve Blass, Network World
April 19, 2007 04:02 PM ET
Steve Blass
  • Print

What can be done to minimize exposure to the current Windows DNS server exploit while we wait for an effective patch?

Those running Windows DNS Server services should check whether the service is configured to accept Remote Procedure Call requests and disable them if possible. The SANS Institute Internet Storm Center reports that new variants of the Rinbot worm are actively scanning RPC/DNS Port 1025 to identify targets against which to attempt to perform a Windows DnsservQuery to exploit the DNS RPC vulnerability. Microsoft recommends disabling remote management over RPC for the DNS server by modifying the registry, blocking unsolicited inbound traffic on ports 1024-5000 using a firewall, and enabling the advanced TCP/IP filtering options on outward-facing interfaces. I used this opportunity to replace the Microsoft DNS server with the latest version of the Berkeley Internet Name Domain, BIND 9.4 from the Internet Software Consortium. Windows is officially supported in the latest releases of BIND, and there are compiled binary distributions available for download. BIND supports all the record types required by Windows and provides better dynamic DNS handling, which results in fewer unnecessary DNS lookups and slightly better overall network performance. If you can't disable or block the RPC/DNS ports, restarting the Windows DNS Server service regularly may provide some relief while waiting for the next Microsoft patch.

Read more about security in Network World's Security section.

  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Videos

rssRss Feed