Domain risk worse than I thought

Opinion
Oct 24, 20051 min

This just in: 75% of DNS servers are open to cache poisoning and denial of service attacks, according to an Infoblox survey of 1.3 million sampled domains, in conjunction with The Measurement Factory. The implications for pharming then, are worse than I’d imagined when I wrote a story about preventing domain hijacking and DNS cache poisoning back in July for Networkworld. No wonder that article was a top read read for two weeks running. More of the Infoblox survey follows: · There are an estimated 7.5 million external DNS servers on the public Internet. · Over 40% allow zone transfers from arbitrary queriers. This exposes a name server to denial of service attacks and gives attackers information about internal networks. · In almost 33% of the cases, all authoritative name servers for a zone were on the /24 same subnetwork. This leaves network open to accidental and deliberate denial of service attacks. · Only 60% of the name server records delegating each zone matched the intrazone name server records . Mis-matched records may decrease the number of servers available for resolution, reduce redundancy, increase load, and leave a zone susceptible to denial of service attacks.

deb_radcliff

Deb Radcliff is an investigative journalist and analyst focused on computer crime and security. Her work has appeared on Security Boulevard, the SANS Cyber Security Blog, and SC Media, among other outlets. She stood up an analyst program for SANS Institute and ran it for 15 years before joining the Cyber Risk Alliance as strategic analyst on the business intelligence unit. She is author of the popular cyber thriller series, “Breaking Backbones,” available at Amazon.

Deb won two Neal Awards for investigative business reporting. She holds a Bachelor’s degree in journalism from San Jose State University.

More from this author