DNS cache poisoning attacks return due to Linux weakness

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Forum Veteran
Aug 17, 2014
12,729
123,838
8,399
Researchers from Tsinghua University and the University of California have identified a new method that can be used to conduct DNS cache poisoning attacks.
The new discovery revives a 2008 bug that had once been thought to have resolved for good. [...]
Update 13-Nov-2020: Added, this vulnerability is being tracked as CVE-2020-25705. Added solutions proposed by the researchers.
Additionally, according to the researchers, the vulnerability also impacts other operating systems shown below for which a patch has not yet been issued.
"In addition to Linux, we have verified that other major OS kernels are vulnerable as well, albeit with lower global rate limit — 200 in Windows and FreeBSD, and 250 in MacOS," state the researchers in their paper.
 
Last week I noticed my linux DNS performance was weak. Had to clear all the current entries and restarting the service couple of times resolved it.
Didn't know DNS vulnerability was present. Usually I read the changelogs to updates in synaptic. systemd-resolve was the component I was taking which is present in Ubuntu distros.
 

You may also like...