{"id":134238,"date":"2015-08-05T16:51:47","date_gmt":"2015-08-05T14:51:47","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=134238"},"modified":"2015-08-05T16:53:05","modified_gmt":"2015-08-05T14:53:05","slug":"massive-dns-bug-allows-easy-dos-attack","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/134238-massive-dns-bug-allows-easy-dos-attack.html","title":{"rendered":"Massive DNS bug allows easy DoS attack"},"content":{"rendered":"<p>The Internet Systems Consortium (ISC) recently released a security patch for Bind, a domain name system (DNS) server used by websites and hosting services.<\/p>\n<p>It fixed an issue in Bind which allowed attackers to crash it, which could make a website unreachable to visitors.<\/p>\n<p>DNS resolves a domain name, such as mybroadband.co.za, into the IP address of the server where the associated website or service is located.<\/p>\n<p>Security vendor Sucuri explained that <strong><a href=\"https:\/\/blog.sucuri.net\/2015\/08\/bind9-denial-of-service-exploit-in-the-wild.html\" target=\"_blank\">DNS is a\u00a0critical part of Internet infrastructure<\/a><\/strong>. If you knock the name servers of a domain offline, e-mail, HTTP, and other services linked to that domain will be unavailable.<\/p>\n<p>The vulnerability exists because of the way Bind handles TKEY queries. According to Sucuri, a single UDP packet can trigger an assertion failure, causing the DNS daemon to exit.<\/p>\n<p>Although the ISC released a patch along with security advisory <strong><a href=\"https:\/\/kb.isc.org\/article\/AA-01272\/74\/CVE-2015-5477%3A-An-error-in-handling-TKEY-queries-can-cause-named-to-exit-with-a-REQUIRE-assertion-failure.html\" target=\"_blank\">CVE\u20132015\u20135477<\/a><\/strong>, sites remain unpatched.<\/p>\n<p>It said patches are available for all major Linux distributions, and can be installed with commands (\u201cyum update\u201d on Red Hat\/Centos and \u201capt-get update\u201d on Debian-based systems).<\/p>\n<p>Sucuri said those who run their own DNS servers must look for any type of TKEY request in their\u00a0DNS logs to see if they are being targeted.<\/p>\n<h3 id=\"related\">More security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134094-hackers-are-costing-south-africa-millions.html\"><strong>Hackers are costing South Africa millions<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134086-apple-os-x-vulnerable-to-big-0-day-security-flaw.html\"><strong>Apple OS X vulnerable to big 0-day security flaw<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/133590-trust-in-government-departments-private-companies-leads-to-identity-theft.html\"><strong>Trust in government departments, private companies leads to identity theft<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/133430-your-android-smartphone-can-be-hacked-with-one-message.html\"><strong>Your Android smartphone can be hacked with one message<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Even after releasing a patch for a serious vulnerability in the Bind DNS server, websites have been attacked and taken offline.<\/p>\n","protected":false},"author":23,"featured_media":134244,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[36,23573,19564,31906,31908],"class_list":["post-134238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-denial-of-service","tag-domain-name-system-dns","tag-internet-systems-consortium-isc","tag-tkey"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134238"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=134238"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134238\/revisions"}],"predecessor-version":[{"id":134246,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134238\/revisions\/134246"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/134244"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=134238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=134238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=134238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}