, 11 2017 . 17:12
+
DNS- BIND
. DNS- (dns zone transfer attack).
CVE-2017-3143 BIND DNS TSIG. TSIG DNS- PowerDNS, NSD Knot DNS.
Synacktiv TSIG-, , (key name) , .
TSIG- ( , ), , , . TSIG. DNS-.
RFC 2845, :
- (MAC) ;
- (), TSIG;
- TSIG, .
, :
- DNS SOA, RR , . , TXT Injected. , , , 32 HMAC-SHA256.
- , MAC () TSIG, , TXT, .
- , , 1, , MAC TSIG, Zones SOA, MAC 2. , Time Signed TSIG , .
- , , , :
14-Jun-2017 07:48:55.003 client 172.17.42.1#50445/key tsig_key: updating zone 'example.com/IN': adding an RR at 'i.can.inject.records.in.the.zone.example.com' TXT "injected"
, BIND:
- BIND 9.9.10
- BIND 9.10.5
- BIND 9.11.1
ISC, BIND, :
- 9.4.0 9.8.8
- 9.9.0 9.9.10P1
- 9.10.0 9.10.5P1
- 9.11.0 9.11.1P1
- 9.9.3S1 9.9.10S2
- 9.10.5S1 9.10.5S2
Synaktiv PoC- .
ISC
. , Positive Technologies IDS Suricata, CVE-2017-3143 , :
MaxPatrol 8.
https://habrahabr.ru/post/332880/
:
author ptsecurity
positive technologies
dns
bind
tsig