Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft virtualization tools reinforce user's data center plans
Air traffic network glitch cleared-up for now
Cisco buys into e-mail with $215 million PostPath acquisition
Locked iPhones can be unlocked without a password
Baseball's video and secure telephone links ready for instant replay
China aims for petaflop computer in 2010
Mozilla garners praise over Firefox security feature
Mt. Sinai Medical Center looks to open standards for patient smartcards
Immersion to pay Microsoft $20 million to settle patent suit
Expand Networks secures $8.5 million in venture capital
Alcatel-Lucent intros Gigabit Ethernet switches
Storage market thrives in down economy
Hosted RFID service targets mobile users
Best Western downplays data breach
Google drops Bluetooth, GTalkService APIs from Android 1.0
Security /

CERT warns of another BIND problem

Today's breaking news
Send to a friendFeedback

Advertisement:


A flaw in a software tool used to translate text-based Internet domain names into numerical addresses could make parts of the Internet vulnerable to denial-of-service attacks, the Computer Emergency Response Team warned Tuesday.

The flaw is in certain versions of BIND [Berkeley Internet Name Domain], a widely-used piece of DNS software, CERT said in an advisory.

DNS servers running BIND 9 prior to Version 9.2.1 are vulnerable. An attacker could shut down the DNS service on that server by sending a specific DNS packet. The service will then remain unavailable until restarted, CERT said.

Advertisement:

BIND 9.2.1 was released on May 1 by the Internet Software Consortium (ISC), which distributes BIND free of charge. It is a so-called maintenance release that fixes a number of bugs in 9.2.0 but has no new features, according to the ISC Web site.

DNS servers translate text-based domain names into numeric IP addresses. When those servers go down, users who type Web addresses - such as nba.com and fbi.gov - can't connect to the intended servers. E-mail sent to affected domains will bounce back.

"If you can trigger something that shuts down the name server, than that is a serious matter," said Petur Petursson, CEO of Men & Mice, a DNS consultancy firm in Reykjavik, Iceland.

"It is normal for a company to run two name servers. If you manage to shoot both of them down, the company will disappear from the Internet," Petursson said.

BIND 9.2.1 is available for free download from the ISC Web site. BIND is also often part of software sold by server software vendors. These vendors may offer their own patches, according to CERT, which urges users of BIND 9 to either upgrade or apply a patch.

The vulnerability of the DNS is seen as an important Internet security concern. The Internet Corporation for Assigned Names and Numbers, the organization that oversees the Internet's addressing system, has formed a security committee aimed, in part, at examining DNS security holes.

The IDG News Service is a Network World affiliate.

RELATED LINKS

US border agency says it can seize laptops 8/1/2008
US Air Force lets Web 2.0 flourish behind walls 7/17/2008
ACLU files lawsuit to challenge surveillance law 7/10/2008
Powered by Inform

Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

Get Copyright Clearance
Request a reprint or permission to use this article.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.