{"id":82460,"date":"2020-05-21T19:42:00","date_gmt":"2020-05-21T17:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery"},"modified":"2020-05-21T19:42:00","modified_gmt":"2020-05-21T17:42:00","slug":"ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery","title":{"rendered":"NXNSAttack, affecting all DNS resolvers","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A group of researchers from Tel Aviv University and the Interdisciplinary Center in Herzliya (Israel) <noindex><a rel=\"nofollow\" href=\"https:\/\/en.blog.nic.cz\/2020\/05\/19\/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack\/\">developed<\/a><\/noindex> a new attack method <noindex><a rel=\"nofollow\" href=\"http:\/\/www.nxnsattack.com\/\">NXNSAttack<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"http:\/\/www.nxnsattack.com\/dns-ns-paper.pdf\">PDF<\/a><\/noindex>), which allows any DNS resolvers to be used as traffic amplifiers, achieving amplification factors of up to 1621 times in the number of packets (for each request sent to the resolver, up to 1621 requests can be sent to the victim's server) and up to 163 times in traffic. <\/p>\n<p>The problem is related to the protocol's characteristics and affects all DNS servers that support recursive processing of requests, including <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/bind-announce@lists.isc.org\/msg00571.html\">BIND<\/a><\/noindex> (CVE-2020-8616), <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/05\/19\/2\">Knot<\/a><\/noindex> (CVE-2020-12667), <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/05\/19\/3\">PowerDNS<\/a><\/noindex> (CVE-2020-10995), <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200009\">Windows DNS Server<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/05\/19\/5\">Unbound<\/a><\/noindex> (CVE-2020-12662), as well as public DNS services from Google, Cloudflare, Amazon, Quad9, ICANN, and others. The issue was coordinated with the DNS server developers, who simultaneously released updates to address the vulnerability in their products. Protection against the attack has been implemented in the releases<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/nlnetlabs.nl\/news\/2020\/May\/19\/unbound-1.10.1-released\/\">Unbound 1.10.1<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.knot-resolver.cz\/2020-05-19-knot-resolver-5.1.1.html\">Knot Resolver 5.1.1<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/downloads.powerdns.com\/releases\">PowerDNS Recursor 4.3.1, 4.2.2, 4.1.16<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/bind-announce@lists.isc.org\/msg00573.html\">BIND 9.11.19, 9.14.12, 9.16.3<\/a><\/noindex>.<\/p>\n<p>The attack relies on the attacker using queries that reference numerous previously unseen fictitious NS records, which are delegated to determine the name but do not provide glue records containing information about the IP addresses of the NS servers in the response. For example, the attacker sends a request to resolve the name sd1.attacker.com while controlling the DNS server responsible for the domain attacker.com. In response to the resolver's inquiry to the attacker's DNS server, a reply is issued delegating the resolution of the address sd1.attacker.com to the victim's DNS server by specifying NS records in the response without detailing the NS servers' IP addresses. Since the mentioned NS server has not been seen previously and its IP address is not specified, the resolver attempts to resolve the IP address of the NS server by directing a query to the victim's DNS server servicing the target domain (victim.com).<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"http:\/\/www.nxnsattack.com\/dns-ns-paper.pdf\"><img decoding=\"async\" alt=\"NXNSAttack, affecting all DNS resolvers\" src=\"\/wp-content\/uploads\/2020\/05\/d56af64ec0f47b2673bd6ff5869e1087.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>The problem is that an attacker can respond with a huge list of non-repeating NS servers with nonexistent dummy subdomain names of the victim (fake-1.victim.com, fake-2.victim.com,\u2026 fake-1000.victim.com). The resolver will attempt to send a request to the victim's DNS server but will get a response indicating that the domain is not found, after which it will try to determine the next NS server in the list, and so on, until it has checked all the NS records listed by the attacker. Consequently, for one request from the attacker, the resolver will send a massive number of requests to determine the NS hosts. Since the NS server names are randomly generated and refer to nonexistent subdomains, they are not retrieved from the cache, and each request from the attacker leads to a barrage of requests to the DNS server servicing the victim's domain.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/en.blog.nic.cz\/2020\/05\/19\/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack\/\"><img decoding=\"async\" alt=\"NXNSAttack, affecting all DNS resolvers\" src=\"\/wp-content\/uploads\/2020\/05\/9a1ca424c949d7732ce361560ff71e0c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Researchers have studied the extent to which public DNS resolvers are susceptible to the problem and found that when sending requests to the CloudFlare resolver (1.1.1.1), a packet amplification factor (PAF) of up to 48 times can be achieved, while Google (8.8.8.8) achieves 30 times, FreeDNS (37.235.1.174) 50 times, and OpenDNS (208.67.222.222) 32 times. More significant figures are observed for<br \/>\nLevel3 (209.244.0.3) - 273 times, Quad9 (9.9.9.9) - 415 times.<br \/>\nSafeDNS (195.46.39.39) - 274 times, Verisign (64.6.64.6) - 202 times.<br \/>\nUltra (156.154.71.1) - 405 times, Comodo Secure (8.26.56.26) - 435 times, DNS.Watch (84.200.69.80) - 486 times, and Norton ConnectSafe (199.85.126.10) - 569 times. For servers based on BIND 9.12.3, due to request parallelization, amplification levels can reach up to 1000. In Knot Resolver 5.1.0, the amplification level is around several dozen times (24-48), as the determination of NS names is performed sequentially and is limited by an internal cap on the number of resolution steps allowed for a single request.<\/p>\n<p>Two main defense strategies are highlighted. For systems with DNSSEC <noindex><a rel=\"nofollow\" href=\"https:\/\/en.blog.nic.cz\/2020\/05\/19\/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack\/\">offered<\/a><\/noindex> to use <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8198\">RFC-8198<\/a><\/noindex> to prevent cache bypass since requests are sent with random names. The essence of the method is generating negative responses without querying authoritative DNS servers, using range checks through DNSSEC. A simpler method is to limit the number of names that can be resolved per delegated request, but this method may cause issues with some existing configurations, as limits are not defined in the protocol.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52995\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0422\u0435\u043b\u044c-\u0410\u0432\u0438\u0432\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438 \u041c\u0435\u0436\u0434\u0438\u0441\u0446\u0438\u043f\u043b\u0438\u043d\u0430\u0440\u043d\u043e\u0433\u043e \u0446\u0435\u043d\u0442\u0440\u0430 \u0432 \u0413\u0435\u0440\u0446\u043b\u0438\u0438 (\u0418\u0437\u0440\u0430\u0438\u043b\u044c) \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 NXNSAttack (PDF), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u043b\u044e\u0431\u044b\u0435 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440\u044b \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0443\u0441\u0438\u043b\u0438\u0442\u0435\u043b\u0435\u0439 \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u0441\u0442\u0435\u043f\u0435\u043d\u044c \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f \u0434\u043e 1621 \u0440\u0430\u0437 \u043f\u043e \u0447\u0438\u0441\u043b\u0443 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 (\u043d\u0430 \u043a\u0430\u0436\u0434\u044b\u0439 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u043a \u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440\u0443 \u0437\u0430\u043f\u0440\u043e\u0441, \u043c\u043e\u0436\u043d\u043e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u0436\u0435\u0440\u0442\u0432\u044b 1621 \u0437\u0430\u043f\u0440\u043e\u0441) \u0438 \u0434\u043e 163 \u0440\u0430\u0437 \u043f\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0443. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":82461,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-82460","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0422\u0435\u043b\u044c-\u0410\u0432\u0438\u0432\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438 \u041c\u0435\u0436\u0434\u0438\u0441\u0446\u0438\u043f\u043b\u0438\u043d\u0430\u0440\u043d\u043e\u0433\u043e \u0446\u0435\u043d\u0442\u0440\u0430 \u0432 \u0413\u0435\u0440\u0446\u043b\u0438\u0438 (\u0418\u0437\u0440\u0430\u0438\u043b\u044c)\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 NXNSAttack, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0430\u044f \u0432\u0441\u0435 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0422\u0435\u043b\u044c-\u0410\u0432\u0438\u0432\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438 \u041c\u0435\u0436\u0434\u0438\u0441\u0446\u0438\u043f\u043b\u0438\u043d\u0430\u0440\u043d\u043e\u0433\u043e \u0446\u0435\u043d\u0442\u0440\u0430 \u0432 \u0413\u0435\u0440\u0446\u043b\u0438\u0438 (\u0418\u0437\u0440\u0430\u0438\u043b\u044c)\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-05-21T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-05-21T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47NXNSAttack, affecting all DNS resolvers | ProHoster","description":"A group of researchers from Tel Aviv University and the Interdisciplinary Center in Herzliya (Israel)","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0430 NXNSAttack, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0430\u044f \u0432\u0441\u0435 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440\u044b | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u0422\u0435\u043b\u044c-\u0410\u0432\u0438\u0432\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0438 \u041c\u0435\u0436\u0434\u0438\u0441\u0446\u0438\u043f\u043b\u0438\u043d\u0430\u0440\u043d\u043e\u0433\u043e \u0446\u0435\u043d\u0442\u0440\u0430 \u0432 \u0413\u0435\u0440\u0446\u043b\u0438\u0438 (\u0418\u0437\u0440\u0430\u0438\u043b\u044c)","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/ataka-nxnsattack-zatragivayushhaya-vse-dns-rezolvery","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-05-21T17:42:00+00:00","article:modified_time":"2020-05-21T17:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"82460","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:37:29","updated":"2022-09-29 14:28:05","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/82460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=82460"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/82460\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/82461"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=82460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=82460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=82460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}