Domain Name System still at risk

Global DNS is 'as vulnerable as ever', reports Infoblox

Written by Ian Williams

The Domain Name System (DNS) is still growing strongly, indicating the internet's expansion in terms of infrastructure, users, traffic and applications.

But the annual survey of domain name servers on the public internet by Infoblox suggests that the global DNS is as vulnerable as ever.

DNS servers map domain names to their specific IP address, directing internet inquiries to the appropriate location.

Domain name resolution conducted by these servers is required to perform any internet-related request.

Should an organisation's DNS systems fail, all internet functions, including email, web access, e-commerce and extranets, become unavailable.

The report showed that the DNS infrastructure is modernising and coalescing around the most recent versions of the Berkeley Internet Name Domain (Bind), the most commonly used DNS server software on the internet.

However, the DNS is still vulnerable as many DNS servers are left open to attack from several directions.

More than 50 per cent of internet name servers allow recursive queries, for example, which often require a name server to relay requests to other name servers.

This can leave name servers vulnerable to pharming attacks and allow those servers to be used in DNS amplification attacks that can take down important internet infrastructure.

"For the overall security of the internet, it is good to see movement away from Microsoft DNS Servers for external DNS as well as a growing trend to use the most recent versions of Bind," said Cricket Liu, vice president of architecture at Infoblox.

"However, even with growing adoption of more secure name servers, compromises of these systems are still occurring.

"Organisations need to pay more attention to configurations and deployment architectures that are leaving their DNS infrastructures vulnerable to attacks and outages."

Infoblox reported that internet-facing DNS servers increased to 11.5 million, up from around nine million in 2006 and 7.5 million in 2005, and that use of Bind 9, the latest version, grew to 65 per cent in 2007, up from 61 per cent in 2006.

Furthermore, support for the Sender Policy Framework increased to 12.6 per cent in 2007, up from five per cent in 2006.

SPF allows software to identify and reject forged email addresses and indicates that organisations are taking email fraud seriously.

See also:

reader comments

related articles

Hacking

McAfee paints grim picture for 2008

Huge rise in web 2.0 attacks and smarter botnets 16 Nov 2007

 

Agent Trojan targets Asian gamers

Malware attempts to steal usernames and passwords 15 Nov 2007

TechEd 2007: Security should be taught in schools

More user education and better collaboration needed to beat online threats 14 Nov 2007

Phishing scam taps Salesforce data

Customers being bombarded with attacks 09 Nov 2007

Government ignores Lords advice on online crime

Downing Street accused of 'head in the sand' approach 02 Nov 2007

Hackers can 'wreak havoc' with zero byte scripts

An oldie but a goldie 31 Oct 2007

'Italian job' attacks spread worldwide

10,000 websites now hosting malicious attack code 19 Jun 2007

Storage stats paint disastrous picture

Surveys find that UK firms are not putting adequate disaster recovery plans in place 17 Oct 2007

'Spam King' Soloway arrested in the US

27 year-old accused of using compromised computers to send tens of millions of emails 01 Jun 2007

latest news

Honeyfone Tribunal ruling tastes sweet to HMRC

Mobile phone trader loses tribunal appeal against Extended Verfication policy 16 May 2008

Zultys blasts Milnes for R&D credential outburst

IP telephony vendor claims it is stronger than ever despite claims by former head 16 May 2008

Ricoh resellers benefit from price rise U-turn

UK VARs attending Ricoh’s Partner Summit were heartened by news that the printing vendor has shelved a proposed 9.5 per cent price hike. 16 May 2008

poll

Defeating the pirates?

Defeating the pirates?

Do you think the UK will ever be free from software pirates?

Previous poll results

CRN Product Cast: Cisco Unified Communications

In this exclusive video, commissioned by Cisco, resellers can discover how to reap the benefits of Unified Communications in the SMB space.

Toughbook

CRN product cast: Panasonic Toughbooks

This exclusive video, commissioned by Panasonic, provides a unique demonstration of the latest Toughbook notebooks

events

Channel Expo 2008

Channel Expo 2008

The 2008 Channel Expo in May will be bigger and better than ever

CRN Fight Night logo

CRN Channel Fight Night 2008

CRN's inaugural white-collar boxing event aims to raise money for a variety of good causes

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories