Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Dec 2003
    Posts
    89

    Default PCI - Remote DNS Server is vulnerable to cache snooping

    Been working through pickups for pci compliance

    last deal breaker is the following:-

    The remote DNS server is vulnerable to cache snooping attacks. Risk:
    High UDP Port:
    53
    The remote DNS server responds to queries for third-party domains
    that do not have the recursion bit set.

    This may allow a remote attacker to determine which domains have
    recently been resolved via this name server, and therefore which hosts
    have been recently visited.

    For instance, if an attacker was interested in whether your company
    utilizes the online services of a particular financial institution,
    they would be able to use this attack to build a statistical model
    regarding company usage of that financial institution. Of course, the
    attack can also be used to find B2B partners, web-surfing patterns,
    external mail servers, and more.

    Note: If this is an internal DNS server not accessable to outside
    networks, attacks would be limited to the internal network. This
    may include employees, consultants and potentially users on
    a guest network or WiFi connection if supported.

    Solution:
    Use another DNS software.

    lol the solution seems a bit crude, anyone who is knowledge tell me what i can do to resolve this ?

  2. #2
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    If you are using bind in it's default state, it does have limited 3rd party recursion and zone transfers but you can reconfigure that easy enough to only allow to local address and resolvers that actually have a legitimate need to be directly communication with your server.

  3. #3
    Registered User
    Join Date
    Mar 2010
    Posts
    2

    Default

    Spiral, Can you be a little more specific as what to change and where?

  4. #4
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    Tell you what ....

    Email me a copy of your /etc/resolv.conf and a capture of your "ifconfig" and from that I can probably write you up a quite list of the lines you need to insert and patch to your /etc/named.conf

  5. #5
    Member
    Join Date
    Dec 2003
    Posts
    89

    Default

    I can disable recursion quite easily but this causes a huge issue as the store that operates on the same server cannot then complete the checkout process, it literally gets to a certain point and then goes to a blank screen

    tested this a few times and it is repeatable, with recursion enabled checkout operates fine, with recursion disabled the checkout dails.

    OsCommerce derivative is the framework used on the store btw

Similar Threads & Tags
Similar threads

  1. Remote Dns Server Ip
    By PedFraser-db1 in forum New User Questions
    Replies: 3
    Last Post: 08-19-2009, 02:57 PM
  2. PCI Compliance - DNS Cache Snooping
    By smdstudios in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-26-2009, 01:41 AM
  3. bind server - dns cache
    By vmicovic in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-12-2008, 04:48 AM
  4. DNS Reports showing major error on remote dns server
    By DWHS.net in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-26-2007, 07:56 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube