Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Denial of Service >> Multiple Vendor DNS Response Flooding Denial Of Service


Vulnerability Assessment Details

Multiple Vendor DNS Response Flooding Denial Of Service

Vulnerability Assessment Summary
send malformed DNS query on port 53

Detailed Explanation for this Vulnerability Assessment

Multiple DNS vendors are reported susceptible to a denial of service
vulnerability (Axis Communication, dnrd, Don Moore, Posadis).

This vulnerability results in vulnerable DNS servers entering into an infinite
query and response message loop, leading to the consumption of network and
CPU resources, and denying DNS service to legitimate users.

A possible hacker may exploit this flaw by finding two vulnerable servers and
set up a 'ping-pong' attack between the two hosts.

Solution : http://www.uniras.gov.uk/vuls/2004/758884/index.htm
Network Security Threat Level: Medium

Networks Security ID: 11642

Vulnerability Assessment Copyright: This script is (C)2004 Cedric Tissieres, Objectif Securite

Cables, Connectors

Dell PowerEdge R720 Server Dual E5-2690 8C 2.9GHz 64GB 2x 500GB SAS 8 Bay 2.5in
$1435.0
Dell PowerEdge R720 Server Dual E5-2690 8C 2.9GHz 64GB 2x 500GB SAS 8 Bay 2.5in pictureDell PowerEdge R620. 1*E5-2670 2.6GHz, No Drives, PERC H310, 16GB Ram
$799.0
Dell PowerEdge R620. 1*E5-2670 2.6GHz, No Drives, PERC H310, 16GB Ram pictureDell R720 Dual E5-2660 8C 2.2GHz 96GB 16x 300GB SAS H710 16 Bay 2.5in
$2259.0
Dell R720 Dual E5-2660 8C 2.2GHz 96GB 16x 300GB SAS H710 16 Bay 2.5in pictureDell PowerEdge R720 2x E5-2630 v2 2.6Ghz 6 Core 384GB 8x 300GB 15K SAS H710
$4719.0
Dell PowerEdge R720 2x E5-2630 v2 2.6Ghz 6 Core 384GB 8x 300GB 15K SAS H710 picture


Discussions

No Discussions have been posted on this vulnerability.