HomeSecurityNew vulnerability in DNS servers can be used for large-scale DDoS attacks...

New vulnerability in DNS servers can be used for large-scale DDoS attacks

A group of academics from Israel has revealed information about NXNSAttack, a new vulnerability in DNS servers that can be used for large-scale DDoS attacks. According to the researchers, the new NXNSAttack vulnerability affects recursive DNS servers and the DNS resolution process. Recursive DNS servers are DNS systems that pass DNS queries upstream to resolve and convert a domain name to an IP address. These conversions are performed by authoritative DNS servers, servers that contain a copy of the DNS record and are authorized to resolve it. However, as part of the security of the DNS protocol, authoritative DNS servers can also “delegate” this function to alternative DNS servers of their choice.

New vulnerability in DNS servers can be used for large-scale DDoS attacks

In a newly released study, academics from Tel Aviv University and the Interdisciplinary Center in Herzliya, Israel, said they found a way to abuse this assignment process for DDoS attacks. The NXNSAttack technique has different aspects and variations, but the following are highlighted:

  • An attacker sends a DNS query to a recursive DNS server. The query is for a domain such as “attacker.com”, which is managed through a valid DNS server controlled by an attacker.
  • Since the recursive DNS server is not authorized to resolve this domain, it forwards the operation to the attacker's malicious authoritative DNS server.
  • The malicious DNS server responds to the recursive DNS server with the message “I delegate this DNS resolution operation to this large list of name servers.” The list contains thousands of subdomains from a victim website
  • The recursive DNS server forwards the DNS query to all subdomains in the list, creating an increase in traffic to the victim's official DNS server.
New vulnerability in DNS servers can be used for large-scale DDoS attacks

The research team reports that an attacker exploiting NXNSAttack can amplify a simple DNS query by 2 to 1,620 times its original size, creating a massive increase in traffic that can overwhelm a victim’s DNS server. Once the DNS server is down, this also prevents users from accessing the attacked website, as the website’s domain can no longer be resolved. The research team also notes that the NXNSAttack packet amplification factor (PAF) depends on the software running on a recursive DNS server. However, in most cases, the amplification factor is many times larger than other DDoS amplification attacks, where the PAF is typically between the low values ​​of 2 and 10. This PAF indicates that NXNSAttack is one of the most dangerous DDoS attack vectors known to date, with the potential to carry out debilitating attacks.


Additionally, Israeli researchers said they have been working with DNS software vendors, networks , and managed DNS providers to patch DNS servers around the world in recent months. The affected software includes ISC BIND (CVE-2020-8616), NLnet labs Unbound (CVE-2020-12662), PowerDNS (CVE-2020-10995), and CZ.NIC Knot Resolver (CVE-2020-12667), as well as commercial DNS services provided by companies such as Cloudflare, Google, Amazon, Microsoft, Oracle (DYN), Verisign, IBM Quad9, and ICANN. These patches were released recently and include mitigations that prevent attackers from abusing the DNS resolution process to attack other DNS servers. Finally, server administrators who run their own DNS servers are advised to update their DNS resolution software to the latest version.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS