-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


BIND DNS-

, 11 2017 . 17:12 +


DNS- BIND . DNS- (dns zone transfer attack).


CVE-2017-3143 BIND DNS TSIG. TSIG DNS- PowerDNS, NSD Knot DNS.

Synacktiv TSIG-, , (key name) , .

TSIG- ( , ), , , . TSIG. DNS-.

RFC 2845, :

  • (MAC) ;
  • (), TSIG;
  • TSIG, .

, :

  1. DNS SOA, RR , . , TXT Injected. , , , 32 HMAC-SHA256.
  2. , MAC () TSIG, , TXT, .
  3. , , 1, , MAC TSIG, Zones SOA, MAC 2. , Time Signed TSIG , .
  4. , , , :

14-Jun-2017 07:48:55.003 client 172.17.42.1#50445/key tsig_key: updating zone 'example.com/IN': adding an RR at 'i.can.inject.records.in.the.zone.example.com' TXT "injected"

, BIND:

  • BIND 9.9.10
  • BIND 9.10.5
  • BIND 9.11.1

ISC, BIND, :

  • 9.4.0 9.8.8
  • 9.9.0 9.9.10P1
  • 9.10.0 9.10.5P1
  • 9.11.0 9.11.1P1
  • 9.9.3S1 9.9.10S2
  • 9.10.5S1 9.10.5S2

Synaktiv PoC- .


ISC . , Positive Technologies IDS Suricata, CVE-2017-3143 , :

ISC #BIND #TSIG #Authentication Bypass
CVE-2017-3143
Affected: 9.9 - 9.11#Suricata rules and pcap:https://t.co/guHgAPhsNN https://t.co/LJWhrdKswc

Attack Detection (@AttackDetection) July 10, 2017

MaxPatrol 8.
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/332880/

:  

: [1] []
 

:
: 

: ( )

:

  URL