Best Website-BuildersBest Website-Builders
    What's Hot

    Yes, ChatGPT Is Coming for Your Office Job

    March 10, 2023

    Reddit – Dive into anything

    March 10, 2023

    Trump’s MAGA Cheerleaders in Congress Keep Fragging the Home Team

    March 10, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website-BuildersBest Website-Builders
    • Home
    • CSS

      Jamie Berry Announced as President of Evolver Legal Services

      March 9, 2023

      Parent background visible only from child elements – HTML & CSS – SitePoint Forums

      March 9, 2023

      National Assembly amends standing order to allow CS to attend House of Commons from 23 March » Capital News

      March 9, 2023

      Apple Releases Safari Technology Preview 165 – Brings Bug Fixes and Performance Improvements

      March 9, 2023

      15 Best Courses to Become Full Stack Developer in 2023

      March 9, 2023
    • Joomla

      Web Content Management Systems Market Business Growth Potential 2023-2030

      March 6, 2023

      How to create a successful content strategy framework

      March 3, 2023

      Free Website Hosting Services for Efficient and Reliable Work

      March 2, 2023

      Bluehost Review 2023 – Is It the Fastest Hosting Service?

      March 2, 2023

      Intermediate PHP Developer – IT-Online

      March 1, 2023
    • PHP

      Susana Morales’ family calls for police accountability

      March 10, 2023

      Sheana Shay’s lawyer denies Sheana hit Raquel

      March 10, 2023

      Tennessee Lieutenant Governor Randy McNall comments on men’s thirst trap

      March 9, 2023

      Man charged with spray-painting ‘groomers’ in library, charged with child pornography

      March 9, 2023

      TikTok users are experimenting with M&Ms as eyeshadow and more prison makeup tips

      March 9, 2023
    • UX

      Flipper Zero device seized by Brazilian Telecommunications Authority

      March 10, 2023

      Imagine looking at your job postings on LinkedIn and being paid $32,000 to $90,000 more than you earn.

      March 10, 2023

      SNAP participants in all 53 states and territories were finally able to get their stolen benefits reimbursed, and consumer complaints about credit reporting issues increased 96% in one year.

      March 9, 2023

      What Ethereum’s Latest Rollout Means for ETH and Its Roadmap

      March 9, 2023

      BMW’s iDrive 8.5 updated for smartphone-like user experience

      March 9, 2023
    • Web Builders
      1. Web Design
      2. View All

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      Can Religious Freedom Be Saved? This group is racing the clock to teach America’s first freedom

      February 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023

      Is There A Market For Rap-Themed Slot Games? – Rap Review

      January 19, 2023
    • WordPress

      Intel breaks Cinebench R23 world record with its ultra-powerful Sapphire Rapids chip

      March 9, 2023

      Sorry Gamers, Steam Deck 2 Is A Long Way Ahead

      March 9, 2023

      There’s another really good reason not to illegally stream movies online.

      March 9, 2023

      Google can use the Chrome Cleanup Tool – here’s how to protect your PC.

      March 9, 2023

      Keep an eye on ChatGPT. Discord’s Clyde Comes for Your AI Chatbot Crown

      March 9, 2023
    • Realtoz
      • Our Other Sites
    • More News
    Best Website-BuildersBest Website-Builders
    Home » Lack of security in hidden DNS resolvers leaves website hijacking risk pervasive
    Joomla

    Lack of security in hidden DNS resolvers leaves website hijacking risk pervasive

    websitebuildersnowBy websitebuildersnowOctober 11, 2022No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    WordPress installations exposed to spoofed password resets and cache poisoning threats

    Lack of security in hidden DNS resolvers creates a means to compromise systems by redirecting password reset emails

    Security researchers warn that hidden DNS (Domain Name System) resolvers create a means to carry out email redirection and account takeover attacks.

    In a technical blog post, SEC Consult uses a variant of a cache poisoning attack (PDF) first uncovered by Dan Kaminsky, a well-known network security researcher, to reveal the DNS names of these so-called closed DNS resolvers. It explains how to work with resolution. in 2008.

    Cache from Chaos

    Previous research by SEC Consult has shown that attackers can manipulate DNS name resolution to take over web application user accounts.

    Closed DNS resolvers are used by many hosting providers and other Internet Service Providers (ISPs) to provision their services to their clients. As the name suggests, a closed DNS resolver resides in a closed network or intranet.

    However, the term “closed” is a bit misleading in the context of the SEC Consult study. Because the researchers show that an outside actor could abuse the functionality of his web application to easily attack closed resolvers.

    They found that attack reconnaissance is possible by exploiting how closed DNS resolvers interact with spam protection mechanisms on the open Internet.

    This helps attackers understand DNS security features such as source port randomization, DNSSEC, and IP fragmentation. It could also be understood by an attacker by more easily exploiting the registration, password reset, and newsletter functions of her web application that relies on closed resolvers.

    scour the web

    SEC Consult used two open source tools, DNS Reset Checker and DNS Analysis Server, to analyze DNS traffic from the targeted system and identify vulnerabilities.

    In practice, this attack reconnaissance effort involved sending emails to several known domains and specifying the analysis domain as the sending domain. This allowed researchers to identify thousands of systems using static source ports. This was a security oversight that made it vulnerable to Kaminsky-style attacks.

    “After sending emails to approximately 50,000 domains, we received and analyzed DNS data for approximately 7,000 of them,” explains SEC Consult. “Of these 7,000 domains, he found that at least 25 used static source ports. Digging down the rabbit hole again, he uncovered thousands of domains using static source ports. rice field.”

    SEC Consulting discovered that none of the 25 vulnerable resolver samples used or enforced additional security features such as DNSSEC.

    The affected services ran behind domains operated by both small businesses and large corporations, as well as sites distributing government services and political campaigns.

    Keep up with the latest DNS security news and analysis

    The DNS cache poisoning vulnerability can be exploited for record manipulation and email redirection. This is a security flaw that allows attackers to abuse the password reset functionality of installations such as WordPress and Joomla.

    SEC Consult was able to demonstrate that this attack technique can be used to hijack even a fully patched WordPress installation.

    The information security company has refrained from disclosing the exploit code it developed to attack WordPress systems. This is due to the lack of awareness of this issue and the concern that many web-based systems accessible through closed DNS resolvers may be exposed to attack.

    SEC Consults spoke to ISPs, hosting providers, and Computer Emergency Response Teams (CERTs) about the issue months before last week’s findings were published.

    cash out

    Independent DNS security experts say the research raises legitimate concerns.

    Infoblox Chief DNS Architect Cricket Liu said: Daily Swig: “I don’t think this is particularly new. We talked about this sort of thing when the Kaminsky vulnerability was in its prime, but there are still some DNS servers that don’t use source port randomization.” So this is important.”

    Including Exotic Attacks

    While the traditional Kaminsky attack is definitely not the “next big thing,” according to SEC Consult, it would be unwise to dismiss the issue as unfashionable.

    Timo Longin, security consultant at SEC Consult, said: Daily Swig: “DNS needs to be brought to the attention of the information security community as it offers a very exotic and unknown attack vector. We have discovered several hosting providers that may compromise all your servers.

    Vulnerable DNS resolvers must be patched and securely configured to protect your system. Best practices for securing your own DNS resolver can be found on Google and DNS flag day. Alternatively, you can use a large public DNS provider such as Google, Cloudflare, or Cisco.

    Countermeasures against new DNS attacks are typically quickly implemented by these large providers, according to SEC Consult.

    you might like it too A policy-as-code approach combats “cloud-native” security risks



    Source link

    Share this:

    • Tweet
    • Email
    • Pocket
    • Mastodon
    • WhatsApp
    • Telegram
    • Share on Tumblr
    • Print
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHulu: How to sign up, apps, devices, shows, plans and more
    Next Article Best Free Ecommerce Website Builders (2022) – Forbes Advisor
    websitebuildersnow
    • Website

    Related Posts

    Web Content Management Systems Market Business Growth Potential 2023-2030

    March 6, 2023

    How to create a successful content strategy framework

    March 3, 2023

    Free Website Hosting Services for Efficient and Reliable Work

    March 2, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Yes, ChatGPT Is Coming for Your Office Job

    March 10, 2023

    Reddit – Dive into anything

    March 10, 2023

    Trump’s MAGA Cheerleaders in Congress Keep Fragging the Home Team

    March 10, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.