This just in: 75% of DNS servers are open to cache poisoning and denial of service attacks, according to an Infoblox survey of 1.3 million sampled domains, in conjunction with The Measurement Factory. The implications for pharming then, are worse than I’d imagined when I wrote a story about preventing domain hijacking and DNS cache poisoning back in July for Networkworld. No wonder that article was a top read read for two weeks running. More of the Infoblox survey follows: · There are an estimated 7.5 million external DNS servers on the public Internet. · Over 40% allow zone transfers from arbitrary queriers. This exposes a name server to denial of service attacks and gives attackers information about internal networks. · In almost 33% of the cases, all authoritative name servers for a zone were on the /24 same subnetwork. This leaves network open to accidental and deliberate denial of service attacks. · Only 60% of the name server records delegating each zone matched the intrazone name server records . Mis-matched records may decrease the number of servers available for resolution, reduce redundancy, increase load, and leave a zone susceptible to denial of service attacks.
Domain risk worse than I thought
Opinion
Oct 24, 20051 min




