Cross-Pollination Check

     Security attacks arise in many forms. Attacking a name server is one of them. If you are a name-server operator, the test on vulnerable recursive service from http://recursive.iana.org/ would be a good guide for further investigation on your system.

     The discovery of a highly-effective cache poisoning attack that can affect name servers providing recursive name service has made it important that such servers be patched to mitigate against the problem. Furthermore, the risk of cache poisoning for servers that share recursive and authoritative functions can cross-pollinate the authoritative function with incorrect data. This tool is designed to assess the authorities for a given domain and determine whether they provide vulnerable recursive service.

Well, let’s perform a test on my domain name!

Oh, not bad, right ;)

 

If you were me, which server would you think of next?
- SIIT, Thamasart University (the name server of my institute)

you can also test on tu.ac.th - that will give a similar result.

 

Let’s see neighbor institutes:
- Chulalongkorn University

- Mahidol University

     Now, your turn! check if your server is reliable on its security. If you are a name server operator and you have found such a loophole, it’s high time for you to fix/report the problem.


d0m3z

Leave a Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.