Thank you both for your detailed responses.

What I will pursue at this point is leaving the DNS Servers recursive (we need/prefer 
these two dns servers for lookups for our mail servers), but restrict access to 
recursion via IPSec on the DNS servers.  This way I can leave DNS configured as-is, 
but limit who can do lookups.  Your opinion on this idea?  I assume I can simply 
restrict port 52 INCOMING, to just those IP addresses I choose to allow lookups?

Thanks again -- you guys are great.

marc

> -----Original Message-----
> From: R. Scott Perry [mailto:[EMAIL PROTECTED]
> Sent: Tuesday, February 03, 2004 10:03 AM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] [OT] domain name owner sets his name's
> nameservers to ours; we're not SOA for name
> 
> 
> 
> >We've discovered two or three domain names that are 
> configured to have OUR 
> >name servers as the SOA, but we don't know these people at all.
> ...
> >My understanding is, this was most likely an attempt to 
> hijack our DNS 
> >servers using cache corruption techniques -- techniques for which I 
> >believe we are protected and therefore not vulnerable.  These are 
> >obviously some sort of marketing names, for sales and/or email lists.
> 
> Actually, it doesn't seem to be an attempt to hijack or 
> corrupt your DNS 
> servers.  Most likely, either they entered DNS servers that 
> they knew about 
> (since you have to enter DNS servers when registering a 
> domain), or they 
> thought that you were running an "open DNS server" that 
> anyone could use 
> (in which case they could have had the WHOIS point to their 
> own DNS server, 
> using extremely high TTLs, and then switch back to you, so 
> that your DNS 
> server would return the answers that they want).
> 
> >My two questions are:
> >
> >1.  Do any of you have tests that you run on your DNS 
> servers to verify 
> >they are not vulnerable to cache corruption?  If there are 
> tests I can run 
> >to be sure we're okay, I'd love to hear about them.  We're 
> running MS-DNS, 
> >with all service packs/patches applied, and proper settings 
> in the DNS 
> >server.  From my tests using NSLOOKUP, our servers don't 
> respond in any 
> >way to those names.
> 
> It's not a cache corruption attempt.  Specifically, they do 
> not need to 
> have your NS records in their domains in order to corrupt your 
> cache.  Unfortunately, I am not aware offhand of any tools 
> that check for 
> caches that are vulnerable to corruption.
> 
> However, since you are running an open DNS server (anyone can 
> use it to 
> look up any DNS record -- see 
> http://www.dnsstuff.com/tools/lookup.ch?name=www.google.com&ty
pe=A&server=ns1.webonthefly.com&detail=0 
), you are vulnerable to them feeding your DNS server information on their 
domains, and then listing your DNS servers as their authoritative 
servers.  To get around that, you would need to limit use of your DNS 
servers to people who should have access to it.

>2.  Is there any course of action I can pursue to get these names to not 
>point traffic to our name servers for their zone information, since we'll 
>never have their zone info?

You could try contacting their registrar, although they may not do anything 
about it.

                                                    -Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver 
vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/




To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to