We've discovered two or three domain names that are configured to have OUR name servers as the SOA, but we don't know these people at all.
...
My understanding is, this was most likely an attempt to hijack our DNS servers using cache corruption techniques -- techniques for which I believe we are protected and therefore not vulnerable. These are obviously some sort of marketing names, for sales and/or email lists.

Actually, it doesn't seem to be an attempt to hijack or corrupt your DNS servers. Most likely, either they entered DNS servers that they knew about (since you have to enter DNS servers when registering a domain), or they thought that you were running an "open DNS server" that anyone could use (in which case they could have had the WHOIS point to their own DNS server, using extremely high TTLs, and then switch back to you, so that your DNS server would return the answers that they want).


My two questions are:

1. Do any of you have tests that you run on your DNS servers to verify they are not vulnerable to cache corruption? If there are tests I can run to be sure we're okay, I'd love to hear about them. We're running MS-DNS, with all service packs/patches applied, and proper settings in the DNS server. From my tests using NSLOOKUP, our servers don't respond in any way to those names.

It's not a cache corruption attempt. Specifically, they do not need to have your NS records in their domains in order to corrupt your cache. Unfortunately, I am not aware offhand of any tools that check for caches that are vulnerable to corruption.


However, since you are running an open DNS server (anyone can use it to look up any DNS record -- see http://www.dnsstuff.com/tools/lookup.ch?name=www.google.com&type=A&server=ns1.webonthefly.com&detail=0 ), you are vulnerable to them feeding your DNS server information on their domains, and then listing your DNS servers as their authoritative servers. To get around that, you would need to limit use of your DNS servers to people who should have access to it.

2. Is there any course of action I can pursue to get these names to not point traffic to our name servers for their zone information, since we'll never have their zone info?

You could try contacting their registrar, although they may not do anything about it.


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to