Major fix to DNS vulnerability impacts Windows, Debian

By Scott M. Fulton, III | Published July 8, 2008, 5:57 PM

A very serious flaw in the Internet's DNS servers may have been ripe for a significant exploit, though a familiar security researcher might have sounded the alarm just in time. Now, Microsoft and Linux vendors are responding urgently.

In what appears to be a coordinated effort to fix a well known, though still potentially critical vulnerability to the Domain Name System (DNS) protocol, patches are being deployed today for both Windows and Linux, by both Microsoft and Debian, respectively. These patches would enable a long suggested protocol for validating the source of DNS requests.

The move was apparently motivated by a discovery from security researcher Dan Kaminsky, a penetration testing specialist with IOActive, whose warnings in the past have been known to successfully avert major disasters. This afternoon, the US Department of Homeland Security credited Kaminsky with the discovery. This time the subject is one that Kaminsky has discussed in white-hat security briefings since at least 2003: It's called DNS cache poisoning, and it's a sophisticated form of malicious crafting that can result in traffic being routed to the malicious user's choice of addresses.

The real vulnerability is not in Windows or Linux but in BIND, the most widely deployed DNS software everywhere. A security feature in BIND creates a transaction ID for communications between an IP host and a DNS server. Supposedly, that transaction ID is supposed to be randomized using a 15-bit binary number. But the way it's typically deployed, each limitation or option added to the system reduces the number of bits in that random number by one each time, and reduces the number of guesses a malicious script requires to guess the transaction ID by a power of two.

With that accomplished, a malicious user may be able to effectively "poison" the cache of DNS routers with table entries based on appropriately matching transaction IDs, but which point to improper IP addresses.

Apparently, Kaminsky discovered ways in which a certain arrangement of settings could make that transaction ID relatively predictable with a few rolls of the dice. So this morning, Debian issued a trio of security bulletins, one of which advises administrators, as a workaround, to install local BIND 9 query resolvers that implement source port randomization. This gives the malicious crafter a second set of attributes whose value would have to be guessed, and both random elements combined could augment each other's power exponentially.

It is not an easy or an automatic fix for admins to implement, as this morning's security bulletin makes clear.

Microsoft, meanwhile, made good use of this Patch Tuesday to deploy its own workaround package for various builds and configurations of Windows Server dating back to Windows 2000 Service Pack 4 (see this bulletin for a complete list), and Windows XP Professional -- not Windows Vista. It, too, is not automatic -- previous DNS-related patches may have to be manually uninstalled first, in a particular order.

What the new Microsoft workaround will do is implement a greater number of potential sockets for its own implementation of source port randomization, which will substitute for the usual default port number 53. Since Windows Server 2003, the number of available sockets has been limited to 2500, falling somewhere between port 49152 and 65535. This number of sockets can be reset using a System Registry setting listed in this KnowledgeBase article. Once this value is reset and the package installed, randomization can take place starting at port 1024, and extending for however long the new registry setting allows.

"Because attacks against these vulnerabilities all rely on an attacker's ability to predictably spoof traffic," the DHS' US-CERT division reports today, "the implementation of per-query source port randomization in the server presents a practical mitigation against these attacks within the boundaries of the current protocol specification. Randomized source ports can be used to gain approximately 16 additional bits of randomness in the data that an attacker must guess."

This may not be the final workaround for this potentially serious problem, as today's round of suggestions and patches are in response to temporary measures that are being implemented in BIND. A later patch may involve an improvement to how it generates the address of the stub resolver -- the component in the DNS system which forwards queries to the appropriate server, waits for the response, and then passes that response back. Debian's security advisory today notes no such patch for the stub resolver -- a basic GNU library component -- has been made available, though further advisories should be expected for when it is.

Comments

View comments by with a score of at least

So Kaminsky has published this since "at least" 2003! I think that those like me whose Zonealarm was impacted by the patch can safely remove the patch rather than downgrade their firewall settings given that this vulnerability has not been exploited for at least 5 years.

Score: 0

|

Thanks for the tip.

Score: 0

|

I've already got the Debian bits and pieces through Ubuntu, which is based on Debian. Glad to see that they're being quick about it.

Score: 0

|

People should know that if this is the MS KB951748 update, it is causing a major issue for those using Zone Alarm and I heard Comodo.
It kills your Internet connection.
There have been several workarounds posted on MS and ZA, but nothing that totally seems to work.
I uninstalled the update and hid it until I read of a fix.

Score: 0

|

I got it sorted by dumping ZoneAlarm and installing PC Tools firewall. That worked for me, just wonder how many millions of folk have no idea what to do because they can't get online. This is a problem that should never have been allowed to happen.

Score: 0

|

Here, with Comodo 3.0.25.3778 on XP Pro SP3? No
probs.

Score: 0

|

penetration testing specialist

Sounds like a fancy title for a condom tester...

Score: 0

|

Debian?

Score: 0

|

Its a varient of Linux.

Score: 0

|

...a variant, even. ;)

Couldn't resist.

Score: 0

|

I see that you're still a tool and never will be anything else.....

BTW, only a retard would take that as a compliment.

Score: 0

|

You can tell all of that from some harmless elbowing, eh?

Wow...you must be "special".

Score: 0

|

i know that but... i mmean... linux??

Score: 0

|

i took it as a ****ING compliment you child

Score: 0

|

debian is not a variant, it's a distribution.

Linux is a kernel.

heh

Score: 0

|

Linux is a kernel.

It used to be. Now it's an OS. Common usage trumps book definition....every time.

Score: 0

|

wtf nigga i know it is a variant so **** off

Score: 0

|

Great Job Dan!

Score: 0

|

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Verizon Wireless launches new Android, Chocolate, and ruggedized phones

The lower-priced Eris joins the Droid, while the Chocolate gets a touchscreen and more music playback.

Early sales figures for Windows 7 nicely high, but do we know why?

Fans of triple-digit surges in figures quoted by Betanews will love this one, as it appears Microsoft rediscovered how to pull off a software launch.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.

What hath Mac wrought? A remembrance after a quarter-century

The reason there's a Macintosh today is not because of some brilliant flash of engineering genius, but because Apple had the audacity to learn from its mistakes.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

The iPhone's China syndrome: Sales of 5,000 and climbing

There's actually a country where Apple's device is not a godsend, where sales can be measured in the dozens.

New European counterpart to FCC will ensure 'a more neutral net'

Late Thursday night, the ruling telecom administrators of the EU's member nations signed away their final authority to a new entity overseen by the EC.

Sophos study suggests Windows 7 UAC's default setting is self-defeating

Without any anti-virus installed, a Sophos test showed, User Account Control was only capable of thwarting just one malware package out of ten samples chosen.

Indiscreet tweet trips awareness of Web SSL vulnerability

A group of high-level security engineers had been making progress on thwarting a low-level threat to the Web, until somebody blurted it all out on Twitter.