All the latest UK technology news, reviews and analysis

Zero-day threat takes out DNS servers across the internet

by Phil Muncaster

More from this author

17 Nov 2011

Comment: 1

  • Tweet this

A zero-day vulnerability has been crashing BIND 9 name servers across the internet, leading to service interruptions for scores of organisations in the US, according to an urgent security advisory from the Internet Systems Consortium (ISC).

The ISC rated the flaw as serious, explaining that it could be remotely exploited and that affected DNS servers crashed after "logging an error in query.c with the following message: 'INSIST(! dns_rdataset_isassociated(sigrdataset))'".

"An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers with an assertion failure," the advisory said.

"ISC is working on determining the ultimate cause by which a record with this particular inconsistency is cached."

In the meantime, the ISC has issued a patch to prevent the crashes (see link above).

Web consultant Mark Stockley wrote on the Sophos Naked Security blog that most of the DNS servers on the internet run BIND 9, and that the flaw "appears to be a denial-of-service vulnerability being exploited in the wild".

Matt Barrett, senior solutions architect at vulnerability management firm Rapid7, explained that the first attack was discovered at the National Weather Service in the US, and was followed up by 89 separate attacks on US universities.

"Gone unchecked, this attack could potentially affect nearly the entire internet," he added.

"A temporary patch has already been released, but we encourage everyone to submit packet-capture from their own systems to ISC so they can further investigate."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

C++ GUI Developer - Financial Services - London

C++ GUI Developer - Financial Services - London Tech...

Java Web Developer, Greenfield Trading Application

This is an opportunity for a bright and talented Java...

C# Application Developer

C# Application Developer Location : Nottingham...

Senior HTML Developer

Experienced Web Developer Wanted for Financial Sector...

To send to more than one email address, simply separate each address with a comma.