Update of DNS Server BIND 9.11.18, 9.16.2, and 9.17.1

Published Corrective updates have been released for the stable branches of the BIND DNS server 9.11.18 and 9.16.2, as well as for the experimental branch 9.17.1 currently in development. The new releases has been closed address a security issue related to ineffective protection against "DNS rebinding" when operating in DNS server request forwarding mode (the "forwarders" block in settings). Additionally, efforts have been made to reduce the size of stored DNSSEC digital signature statistics — the number of tracked keys has been reduced to 4 for each zone, which is sufficient in 99% of cases.

The "DNS rebinding" technique allows a user accessing a specific page in their browser to establish a WebSocket connection to a network service in the internal network, which is not directly accessible over the internet. To bypass the cross-origin protection applied in browsers, a hostname change in DNS is used. The attacker's DNS server is configured to alternately return two IP addresses: for the first request, it returns the real IP of the server with the page, and for subsequent requests, it returns the internal address of a device (for example, 192.168.10.1).

The time-to-live (TTL) for the first response is set to the minimum value, so when the page is opened, the browser determines the attacker's real IP address and loads the content of the page. A JavaScript code on the page waits for the TTL to expire and sends a second request, which now identifies the host as 192.168.10.1. This allows JavaScript to access the service within the local network, bypassing the cross-origin restriction. Protection Protection against such attacks in BIND is based on blocking external servers from returning the IP addresses of the current internal network or CNAME aliases for local domains using the deny-answer-addresses and deny-answer-aliases settings.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster