Despite industry efforts to lock down DNS servers, one in four remain vulnerable to cache poisoning due to the well-documented Kaminsky flaw identified earlier this year and another 40 percent could be considered a danger to themselves and others, recent research shows.
According to the fourth annual DNS report issued by The Measurement Factory, 25 percent of DNS servers in the sample group have not been upgraded to perform source port randomization, which is considered the patch for the vulnerability identified earlier this year by Dan Kaminsky, director of penetration testing at IOActive. The industry group bases its study on a sample that includes 5% of the IPv4 address space, or 80 million addresses.
"A surprising number of have not been upgraded and are very vulnerable to cache poisoning," according to a press release from IP address management vendor Infoblox and DNS service and tools provider DNSstuff.
A separate survey of 466 enterprise online customers conducted by DNSstuff in September revealed that 9.6 percent hadn't patched their DNS servers yet and 21.9 percent didn't know if they were patched. The findings show that despite the DNS community's and several vendors' efforts, a significant number of server administrators have yet to take action. As for the reasons behind the lack of patches, more than 45 percent cited a lack of internal resources, 30 percent said they were unaware of the vulnerability and 24 percent reported they didn't have enough knowledge of DNS to take the appropriate steps. DNSstuff's customer research also found that the most common DNS issues include e-mail downtime for 69 percent, distributed denial-of-service (DDoS) attacks and cache poisoning attacks for nearly half of respondents and spoofing for 18.5 percent.
Another potentially worrisome finding is that more than 40 percent of Internet name servers allow recursive queries, leaving "millions of open recursors on the Internet, a danger both to themselves and others -- they are vulnerable to cache poisoning and DDoS attacks," The Measurement Group reports. Another 30 percent of those addresses sampled allow zone transfers to arbitrary requesters, which make servers targets for DoS attacks.
"Even if an enterprise has gone to the trouble of patching against the Kaminsky vulnerability, there are many other aspects of configuration, like recursion and open zone transfers, that should also be secured," said Cricket Lui, vice president of architecture at Infoblox, in a press release. "If not, organizations are essentially locking their door to the house, but leaving the windows wide open."
Latest on Internet Services
- Apache mulls end of 1.3, 2.0 releases
- DNS problem linked to DDoS attacks gets worse
- Businesses turn to DNS service to filter the Web
- Facebook releases real-time Web server tech as open source
- Tr.im goes open-source, founder questions bit.ly-Twitter link
- Open-source project aims to makes secure DNS easier
- SSL VPN hack vulnerability details to emerge
- NeuStar offers temporary fix for Kaminsky bug
- Study: Operators should use DNSSEC to improve security
- Expert: Cybersecurity incentives, not mandates, needed
Open Source Essentials
- Microsoft 'interested' in open source browser: Ballmer
- Flying high with open source
- Open sourcing code may improve transparency on Wall Street
- Problem-solvers hunt open-source solutions
- Open source advocates hail appeals court ruling
- Open-source software a security risk, study claims
- Insurance company bets health on open source
- Open source stack solid foundation for All Homes
- 20 great Windows open source projects you should get to know
- Via releases laptop design as open source
Whitepapers
-
Best Practices for Pipeline Management -
The Pathways ICT Leadership Development Program | Turning today’s ICT professionals into tomorrow’s business leaders -
How Small Businesses Worldwide Use Communications to Thrive in the New Economy -
File Integrity Monitoring: Compliance and Security for Virtual and Physical Environments -
Business Continuity: A Guide to Choosing the Right Technology Solution
TechWorld Blogs
Recent blog posts
- Talk about mobile computing
- iPad arrives: can Apple crack the tablet?
- Linux.conf.au 2010 kicks off in New Zealand
- VMware jumps further into SaaS with Zimbra
- Amarok 2.2.2 released – rock on!
- Happy Nexus Year
- So long 2009, and thanks for another decade in tech
- KDE 4.4 enters beta, bring on mainstream computing
- Chromium OS source released: another way of thinking
- Dell goes Android for mobile market entrance
Recent comments
- Buy 2 get 1 free: Apple iphone 3gs 32gb,Nokia N97,BB Bold,HTC HD
1 hour 3 min ago - My Take:
1 hour 20 min ago - PDA Smart phone users
10 hours 32 min ago - Touch Phone Accessories
10 hours 40 min ago - joo joo
11 hours 31 min ago - Thanks!
1 day 7 hours ago - Transcription mistake
2 days 7 hours ago - Freeway is hardly Australian
2 days 9 hours ago - Great Business Initiative
3 days 4 hours ago - www.mintfly.com
3 days 9 hours ago - also creating unemployment
4 days 1 hour ago - How to save in one page???
5 days 3 hours ago - Well it's 2010 now...
5 days 12 hours ago - Man, catch up. You're being
6 days 13 hours ago - Rhapsody in Australia
6 days 14 hours ago - ipad reaction
1 week 5 hours ago - Capacity Bollenecks
1 week 19 hours ago - not only for "young folks"
1 week 1 day ago - Take action now
1 week 1 day ago - u guys are a idiots. i have
1 week 1 day ago







Comments
Post new comment