|
커피향이 나는 *NIX
커피닉스
시스템/네트웍/보안을 다루는 곳
|
|
|
|
| 이전 주제 보기 :: 다음 주제 보기 |
| 글쓴이 |
메시지 |
truefeel 카페 관리자
가입: 2003년 7월 24일 올린 글: 1277 위치: 대한민국
|
올려짐: 2005.8.03 수, 1:09 am 주제: PowerDNS 서버의 DoS공격 취약점 |
|
|
7월에 Secunia의 권고안에서도 이미 밝힌대로 PowerDNS에 원격 공격에 의한 2가지의 DoS 취약점이 있습니다.
securityfocus에서 8.1일에 취약점에 대한 글이 올라와 있어 다시 한번 살펴봅니다.
- LDAP injection 공격으로 원격지에서 DoS 공격 가능
- recursion query 통한 DoS 공격 가능
이를 해결하기 위해서는 PowerDNS 2.9.18 이상을 사용하기 바랍니다.
지난 7월 초에 개인적으로 국내 1000위(fian.co.kr 기준) 사이트의 DNS를 조사했는데,
1000위 사이트에서 사용중인 DNS서버의 15개가 PowerDNS 2.9.16이하 버전을 사용중이었습니다.
| 코드: |
ns3.????bada.com
ns1.???portal.com
ns2.???portal.com
ns1.???com.com
ns2.???com.com
ns21.???ismall.com
ns21.???is.co.kr
ns1.???fdns.net
ns2.???fdns.net
ns1.???123.co.kr
ns2.???123.co.kr
ns1.????hosting.com
ns1.???isweb.net
ns1.???ycgi.com
|
* 관련글 :
- http://www.securityfocus.com/bid/14291/info
- http://secunia.com/advisories/16111/
| 인용: |
* Description:
Two vulnerabilities have been reported in PowerDNS, which can be exploited by malicious people to cause a DoS (Denial of Service).
1) Queries passed to the LDAP backend are not properly sanitised, which can be exploited to cause the backend to fail and not answer requests.
Successful exploitation requires LDAP backend support.
2) An error in the handling of requests from clients, which are denied recursion, can be exploited to temporarily blank out a domain.
Successful exploitation requires that recursion is provided to a limited range of IP addresses.
The vulnerabilities have been reported in version 2.9.17. Prior versions may also be affected.
* Solution:
Update to version 2.9.18.
http://www.powerdns.com/downloads/
|
|
|
| 위로 |
|
 |
|
|
새로운 주제를 올릴 수 있습니다 답글을 올릴 수 있습니다 주제를 수정할 수 없습니다 올린 글을 삭제할 수 없습니다 투표를 할 수 없습니다
|
Powered by phpBB © 2001, 2005 phpBB Group
|