Cybersecurity experts are warning of a critical vulnerability in the DNS software BIND, which can be exploited for denial of service (DoS) attacks.
The vulnerability (CVE-2015-5477) has been classified as critical, as it affects almost all BIND servers and is very difficult to address.
Note, however, that ordinary internet are not threatened by this type of attack, since BIND is mainly used by internet service providers.
The vulnerability discovered allows attackers to interfere with the software, disabling the DNS service.
The Internet Systems Consortium (ISC), the company that develops Bind, has already released security updates to fix the critical vulnerabilities (BIND 9.10.2-P3 and BIND 9.9.7-P2) since July 28, recommending that Bind users upgrade their systems as soon as possible. In addition, the company revealed in a new announcement that a proof-of-concept (PoC) exploit has already been created, which has been posted to a public source code repository.
Sucuri security researcher Daniel Cid noted that attacks have already been observed in which attackers exploit this vulnerability.
"We confirm that the attacks have begun. DNS is one of the most critical parts of the internet's infrastructure, and if it goes down, email services, HTTP, and all other services become immediately unavailable," he said in a blog post.
Sucuri recommends that DNS Server administrators check their logs for “ANY TKEY” commands to detect possible attack attempts. “Given that TKEY requests are not very common, any TKEY query can be an indication that an attack attempt has been made against the server,” the experts point out.

