DNS cache poisoning attacks return due to Linux weakness

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,176
Researchers from Tsinghua University and the University of California have identified a new method that can be used to conduct DNS cache poisoning attacks.
The new discovery revives a 2008 bug that had once been thought to have resolved for good. [...]
Update 13-Nov-2020: Added, this vulnerability is being tracked as CVE-2020-25705. Added solutions proposed by the researchers.
Additionally, according to the researchers, the vulnerability also impacts other operating systems shown below for which a patch has not yet been issued.
"In addition to Linux, we have verified that other major OS kernels are vulnerable as well, albeit with lower global rate limit — 200 in Windows and FreeBSD, and 250 in MacOS," state the researchers in their paper.
 

Vasudev

Level 33
Verified
Nov 8, 2014
2,230
Last week I noticed my linux DNS performance was weak. Had to clear all the current entries and restarting the service couple of times resolved it.
Didn't know DNS vulnerability was present. Usually I read the changelogs to updates in synaptic. systemd-resolve was the component I was taking which is present in Ubuntu distros.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top